C H A P T E R
4-1
VPN Acceleration Module 2+ (VAM2+) Installation and Configuration Guide
OL-5979-03
4
Configuring the SA-VAM2+
This chapter contains the information and procedures needed to configure the VPN Acceleration
Module 2+ (SA-VAM2+). This chapter contains the following sections:
•
Overview, page 4-1
•
Configuration Tasks, page 4-2
•
Configuration Examples, page 4-21
•
Basic IPSec Configuration Illustration, page 4-22
•
Troubleshooting Tips, page 4-24
•
Monitoring and Maintaining the SA-VAM2+, page 4-26
Overview
The SA-VAM2+ provides encryption services for any interface in the Cisco 7301 router and the
Cisco 7200VXR series routers with a NPE-225, NPE-400, NPE-G1 or NPE-G2 processor. If you have
previously configured IPSec on the router and you install a SA-VAM2+, the SA-VAM2+ automatically
performs encryption services. If you install a second SA-VAM2+, both SA-VAM2+s should be
automatically enabled.
Note
The Cisco 7301 router supports a single SA-VAM2+.
When installing two SA-VAM2+s on the Cisco 7200VXR series routers, per packet load balancing is not
supported. With dual SA-VAM2+s installed, load balancing is done on a per IPSec tunnel basis, rather
than on a per packet basis.
There are no interfaces to configure on the SA-VAM2+.
This section only contains basic configuration information for enabling encryption and IPSec tunneling
services. Refer to the “IP Security and Encryption” part of the
Security Configuration Guide
and the
Security Command Reference
guide for detailed configuration information on IPSec, IKE, and CA.