
Feature Description Guide
© 2010 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 12 of 27
Table 4.
Cisco Configuration Assistant Security Feature Support
Cisco Configuration Assistant Security Feature Support
Category
Feature
v 2.2(5)
v3.0
Description
Firewall
Application firewall
X
X
Provides high, medium, and low security levels for firewall policy
settings to enable accelerated and easy deployment:
● Low: For business environments that do not need to track peer
to peer (P2P) and IM applications on the network or check for
protocol conformance
● Medium: For business environments where security is
important and there is a need to track the use of IM and P2P
applications and check for HTTP and email protocol
conformance
● High: For business environments where security is critical, and
there is a need for protocol anomaly detection services to drop
nonconformant HTTP and email traffic and prevent use of P2P
and IM applications
Zone-based firewall
X
X
Advanced firewall supported by default on Cisco SR500 Series
Secure Router.
URL filtering
X
X
Supported on Cisco SR500 Series Secure Router only.
Intrusion prevention system
(IPS)
X
X
Supported on Cisco SR500 Series Secure Router only.
VPN
Cisco Easy VPN Remote
X
X
Scalable, easy-to-manage, secure remote access for teleworkers
for Cisco SR500 Series
Cisco Easy VPN Server
X
X
Offers wizard-based configuration of remote-access VPN server
configuration for Cisco Unified Communications 500 Series
Secure Sockets Layer (SSL)
VPN
X
X
Split tunneling
X
X
Disable split tunneling
X
X
Uses Dynamic Virtual Tunnel Interface (DVTI) to allow
WAN/Internet access only from VPN hub site
Security Features
Security Setup Wizard
X
X
Cisco SA500 software version 1.1.42 and earlier are not supported
by Cisco Configuration Assistant.
All other SA500 features are configured through the SA500
Configuration Utility, which is accessible from the Cisco
Configuration Assistant Topology view.
SSL- and SSH v2-based
secure remote access
X
X
Provides for secure management between PC and Cisco Unified
Communications 500 Series.
Network Address Translation
(NAT)
X
X
1-to-1 static port mapping for TCP and User Datagram Protocol
(UDP) ports. VoIP pass-through enabled by default on Cisco
SR500 Series Secure Router. Cisco Configuration Assistant 3.0
adds support for 1-to-many static NAT mappings.
Remove NAT and firewall
X
X
Remove NAT and firewall from Cisco Unified Communications 500
Series and Cisco SR500 Series Secure Router for deployments in
network with existing firewall
DMZ
X
X
A DMZ network enables Internet users to access a
company’s
public servers, including web and FTP servers, while maintaining
security for the company’s private LAN.
Security audit
X
X
Assesses vulnerability of existing Cisco Unified Communications
500 Series and Cisco SR500 Series Secure Router.
Provides quick compliance with best-practices (Cisco Technical
Assistance Center [TAC], ICSA recommendations) security policies
for Cisco Unified Communications 500 Series and Cisco SR500
Series Secure Router.
Security diagnostics
X
X
Collect firewall/NAT and VPN debug logs.
Monitoring
X
X
EzVPN client and server, site-to-site VPN, SSL VPN, firewall, NAT,
and VPN status reports.