Cisco AIM-VPN User Guide

Cisco AIM-VPN - DES/3DES VPN Data Encryption AIM Module Manual

Cisco AIM-VPN manual content summary:

  • Cisco AIM-VPN | User Guide - Page 1
    Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) The DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) feature describes how to configure virtual private network (VPN) encryption hardware advanced integration modules (AIM) and network modules (NM) in Cisco
  • Cisco AIM-VPN | User Guide - Page 2
    for DES/3DES/AES VPN Encryption Module Installation Preconditions • Cisco IOS Release 12.2(13)T or later. Note See Table 1 for AIM/VPN Encryption Module support by Cisco IOS Release. • A working IP network For more information about configuring IP, refer to the Cisco IOS IP Configuration Guide
  • Cisco AIM-VPN | User Guide - Page 3
    Module Module AIM-VPN/HPII Hardware Encryption AIM-VPN/HPII-Plus Hardware Encryption Module Module Restrictions for DES/3DES/AES VPN Encryption Module • Rivest-Shamir-Adelman (RSA) manual keying is not supported. • To achieve maximum benefit from hardware-assisted IP Payload Compression Protocol
  • Cisco AIM-VPN | User Guide - Page 4
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) Standards Standards Title No new or modified standards are supported by this - feature, and support for existing standards has not been modified by this feature. MIBs MIBs No new or modified MIBs are supported
  • Cisco AIM-VPN | User Guide - Page 5
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) Command Reference Command Reference This section documents modified commands. All other commands used with this feature are documented in the Cisco IOS Release 12.3 command reference publications. • clear crypto
  • Cisco AIM-VPN | User Guide - Page 6
    clear crypto engine accelerator counter DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) clear crypto engine accelerator counter To reset the statistical and error counters for a router's hardware accelerator to zero, use the clear crypto engine accelerator
  • Cisco AIM-VPN | User Guide - Page 7
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII show crypto engine configuration show crypto engine about each packet sent for encryption and decryption. Displays the contents configuration information for the crypto engine. Displays the version and configuration
  • Cisco AIM-VPN | User Guide - Page 8
    crypto engine accelerator DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) crypto engine accelerator To enable a router's onboard hardware accelerator for IPSec encryption, use the crypto engine accelerator command in global configuration mode. To disable the
  • Cisco AIM-VPN | User Guide - Page 9
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) crypto engine accelerator Related Commands Command clear crypto engine accelerator counter crypto ca crypto cisco crypto dynamic-map crypto ipsec crypto isakmp crypto key crypto map debug crypto engine
  • Cisco AIM-VPN | User Guide - Page 10
    show crypto engine DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine To displays a summary of the configuration information for the crypto engines, use the show crypto engine command in privileged EXEC mode. show crypto engine [brief |
  • Cisco AIM-VPN | User Guide - Page 11
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine Maximum DH index: 2000 Maximum SA index: 2000 Maximum Flow index: 4000 Maximum RSA key size: 2048 crypto engine in slot: 1 crypto engine name: unknown crypto engine type: software serial number:
  • Cisco AIM-VPN | User Guide - Page 12
    show crypto engine accelerator statistic DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine accelerator statistic To display the statistics and error counters for a router's onboard hardware accelerator for IPSec encryption, use the show crypto
  • Cisco AIM-VPN | User Guide - Page 13
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine accelerator statistic 46121 packets in 153 paks/sec in 1667834 Kbits/sec in 0 bytes decrypted 0 Kbits/sec decrypted 1.0:1 compression for plus and non-plus VPN encryption modules is identical
  • Cisco AIM-VPN | User Guide - Page 14
    show crypto engine accelerator statistic DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) Table 3 show crypto engine accelerator statistic Field Descriptions Counter bytes after encrypt packets decompressed packets compressed bytes before decomp bytes before
  • Cisco AIM-VPN | User Guide - Page 15
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine accelerator statistic Router# show crypto engine accelerator statistics Hardware VPN0/2: ds: 0x81C96D98 idb:0x81C93C34 Statistics for Encryption Module 0 packet overruns 0 packets in 0
  • Cisco AIM-VPN | User Guide - Page 16
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) Table 4 show crypto engine accelerator statistic Compression Statistics Descriptions for a Cisco 2600, Cisco 3600 or Cisco 3700 VPN module SPI in the packet's 4615 AH protocol flow. absent The AH sequence check
  • Cisco AIM-VPN | User Guide - Page 17
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine accelerator statistic Table 4 show crypto engine accelerator statistic Compression Statistics Descriptions for a Cisco 2600, Cisco 3600 or Cisco 3700 VPN module Count Label Significance
  • Cisco AIM-VPN | User Guide - Page 18
    show crypto engine accelerator statistic DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) Table 4 show crypto engine accelerator statistic Compression Statistics Descriptions for a Cisco 2600, Cisco 3600 or Cisco 3700 VPN module Count Label cgx_cmd_pending
  • Cisco AIM-VPN | User Guide - Page 19
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show crypto engine accelerator ring show crypto engine accelerator ring To display the contents and status of the control command, transmit packet, and receive packet rings used by the hardware accelerator crypto
  • Cisco AIM-VPN | User Guide - Page 20
    show crypto engine accelerator ring DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) free ring:head = 0 tail =255 00000000 071A96C5 00000000 071A96C5 00000001 071A9465 00000001 071A9465 00000002 071A9205 00000002 071A9205 . . . Related Commands Command clear
  • Cisco AIM-VPN | User Guide - Page 21
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) show diag show diag To display hardware information for a router, use the show diag command in privileged EXEC mode. show diag [slot] Syntax Description slot (Optional) Slot number of the interface. Command
  • Cisco AIM-VPN | User Guide - Page 22
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII EEPROM contents (hex) EEPROM format version Hardware Revision Part Number PCB Serial Number Port . Version number of the EEPROM format. Version number of the Cisco 2611 series port adapter. Part number of the port adapter.
  • Cisco AIM-VPN | User Guide - Page 23
    DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII Family) Glossary Glossary AH-Authentication Header. A protocol for authentication of packets (header included). AIM-advanced integration module. APCI-based card type used on C26xx and C36xx routers. DES-Data Encryption
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23

Corporate Headquarters:
Copyright © 2004 Cisco Systems, Inc. All rights reserved.
Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706
USA
DES/3DES/AES VPN Encryption Module
(AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII
Family)
The DES/3DES/AES VPN Encryption Module (AIM-VPN/EPII, AIM-VPN/HPII, AIM-VPN/BPII
Family) feature describes how to configure virtual private network (VPN) encryption hardware advanced
integration modules (AIM) and network modules (NM) in Cisco IOS Release 12.3(7)T.
Feature Specifications for the VPN Encryption Module
Finding Support Information for Platforms and Cisco IOS Software Images
Use Cisco Feature Navigator to find information about platform support and Cisco IOS software image
support. Access Cisco Feature Navigator at
. You must have an account on
Cisco.com. If you do not have an account or have forgotten your username or password, click
Cancel
at
the login dialog box and follow the instructions that appear.
Feature History
Release
Modification
12.2(13)T
This feature was introduced on the Cisco 2691, Cisco 3660, Cisco 3725,
and Cisco 3745.
12.2(15)ZJ
This feature was introduced on the AIM-VPN/BPII on the following
platforms: Cisco 2610XM, Cisco 2611XM, Cisco 2620XM,
Cisco 2621XM, Cisco 2650XM, and Cisco 2651XM.
12.3(4)T
This feature was integrated into Cisco IOS Release 12.3(4)T.
12.3(5)
This feature was revised to include support for the AIM-VPN/EPII,
AIM-VPN/HPII family of encryption modules and was integrated into
Cisco IOS Release 12.3(5).
12.3(6)
This feature was revised to include support for the AIM-VPN/BPII-Plus on
the 2600XM encryption modules and was integrated into Cisco IOS
Release 12.3(6).
12.3(7)T
This feature was revised to include support for the AIM-VPN/BPII-Plus
family of encryption modules and was integrated into Cisco IOS Release
12.3(7)T.