Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Cisco VPN 3000 Concentrator Features

Nov 02,2009 by alperen

image

The following summarizes the features and benefits provided by the Cisco VPN 3000 Concentrator devices. Chapter 14 addresses those that require configuration.

Modular Design (Models 3015 to 3080)

The Cisco SEP modules provide hardware-based encryption, ensuring consistent performance throughout the rated capacity for models 3030 through 3080. With multiple SEP modules, the devices became distributed-processing architecture, providing enhanced performance and increased reliability through redundancy. This modular design provides investment protection, redundancy, and a simple upgrade path, plus it minimizes the impact on rack space and power supply allocation.

Digital Design

The all-digital design of the VPN 3000 device provides high-degree reliability with solid, long-term performance, while providing 24-hour continuous operation. Incorporated into each unit is a robust instrumentation package for real-time monitoring and alerts.

Security

The VPN 3000 Series support for current and emerging security standards, including RADIUS, NT Domain Authentication, RSA SecurID, one-time passwords (OTP), and digital certificates offering large-scale client deployment and seamless integration with external authentication systems, as well as interoperability with third-party products.

VPN 3000 release 3.6 offers two notable enhancements to concentrator encryption and security, including

  • Advanced Encryption Standard (AES) addition to the concentrator offers a stronger encryption option and provides performance benefits for both the Cisco VPN 3002 Hardware Client and the Cisco VPN Client.

  • RSA SecurID (SDI) Version 5.0 support. Users can now take advantage of the load balancing and resiliency features found in the RSA SecurID Version 5.0.

Advanced packet-filtering capabilities provide additional network security. Filtering options include source and destination IP address (Layer 3), port and protocol type (Layer 4), fragment protection, time and day access control, and FTP session filtering.

User and group-level policy management can be implemented for maximum flexibility and granularity in controlling network and feature access control.

Robust Management

The Cisco VPN 3000 Concentrator can be managed using web-based applications from any standard web browser using HTTP or HTTPS. The VPN 3000s also support CLI commands using Telnet, Secure HTTP, SSH, and via a console port.

The VPN concentrator devices support configuration and monitoring capabilities for both the enterprise user and the service provider.

VPN concentrator device access levels can be configured per user and/or per group allowing configuration and maintenance control consistent with the organization security policies.

Monitoring and Logging

The Cisco VPN 3000 Concentrators support the following technologies for providing monitoring and logging services:

  • Syslog output

  • Configurable SNMP traps

  • Event logging and notification via e-mail (SMTP) and, therefore, pager

  • Automatic FTP backup of event logs

  • SNMP MIB-II support

    General Statistics

    System Status

    Session Data (including Client Assigned IP, Encrypted Type Connection Duration, Client OS, Version, and so forth)


633 times read

Related news

» Cisco Products Enable a Secure VPN
by alperen posted on Oct 30,2009
» Cisco VPN 3000 Concentrator Devices
by alperen posted on Nov 02,2009
» Cisco VPN Hardware Overview Review
by alperen posted on Nov 04,2009
» VPN 3000 Concentrator Client Support
by alperen posted on Nov 02,2009
» IPSec Support in Cisco Systems Products
by alperen posted on Sep 27,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author