Cisco ASA 5500 Series Adaptive Security Appliance Platforms

5510

5520

5540

5540

Security Plus

VPN Plus

VPN Plus

VPN Premium

Simultaneo us Web VPN (clientless) users

■ 150 1

750 I

1 1250

1 |2500 ■

Site-to-site tunnels and remote access server (RAS) VPN peers

150

750

2000

5000

Encrypted throughput (Mbps)

170

225

325

325

Firewall throughput

300

450

650

650

Hardware encryption

Yes

Yes

Yes

Yes

The table shows how the performance of Cisco ASA 5500 Series Adaptive Security Appliances depends on the platform feature license used. Here are the available licenses:

Cisco ASA 5510 Adaptive Security Appliance: Base license and Security Plus license

■ Cisco ASA 5520 Adaptive Security Appliance: Base license with VPN Plus add-on license

■ Cisco ASA 5540 Adaptive Security Appliance: Base license with VPN Plus or VPN Premium add-on license

Cisco ASA 5500 Series Adaptive Security Appliances provide these feature, encryption, and platform licensing options:

■ Feature licenses: These licenses are used to enable additional features such as security contexts and General Packet Radio Service (GPRS) tunneling protocol (GTP) inspection. The available feature licenses are as follows:

— Security context licenses

— GTP inspection license

■ Encryption licenses: These licenses are used to extend the encryption capabilities to 3DES and AES. By default, there are 56-bit DES, 56-bit RC4, 512-bit Rivest, Shamir, and Adleman (RSA), and 512-bit Directory System Agent (DSA) encryptions available.

■ Platform licenses: Various platform licenses are available based on the Cisco security appliance used.

— Cisco ASA 5510 Security Plus license: This license increases port density on the platform by enabling the fourth Fast Ethernet port and removing restriction on the out-of-band (OOB) management port so that the port can be repurposed to a general traffic port if desired. Integration into switched network environments is simplified with this license, because support for up to 10 VLANs is enabled. Furthermore, this upgrade license enables active and standby high availability services and triples VPN capacity by supporting up to 150 concurrent VPN connections.

6-102 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

— Cisco ASA 5520 VPN Plus license: This license more than doubles the platform VPN capacity to support up to 750 concurrent VPN connections from mobile users, remote sites, and business partners.

— Cisco ASA 5540 VPN Plus and VPN Premium licenses: With a VPN Plus license, businesses quadruple the platform base VPN capacity to support up to 2000 concurrent IPsec VPN and 1250 Cisco IOS WebVPN connections from mobile users, remote sites, and business partners. The Cisco VPN Premium license maximizes the platform VPN capacity and offers 10 times the capacity of the base platform, supporting up to 5000 concurrent IPsec VPN and 2500 Cisco IOS WebVPN connections.

© 2006 Cisco Systems, Inc. Building IPsec VPNs 6-103

Cisco PIX 500 Series Security Appliances

• Spoke-to-spoke VPN support

• VPN NAT transparency

• Cisco VPN Client security posture enforcement

• Cisco VPN Client blocking by operating system and type

• OSPF dynamic routing Over VPN

VPN hardware acceleration

The Cisco PIX 500 Series Security Appliances offer extensive features to deploy VPN service.

The features of Cisco PIX 500 Series Security Appliances with Cisco IOS Release 7.0 and above include these capabilities:

■ Enhanced spoke-to-spoke VPN support: Support for spoke-to-spoke (and client-to-client) VPN communications allows encrypted traffic to enter and leave the same interface. Furthermore, split tunnel remote-access connections can now be terminated on the outside interface for the firewall allowing Internet-destined traffic from remote-access user VPN tunnels to leave on the same interface that it arrived on.

■ VPN Network Address Translation (NAT) transparency: Cisco PIX 500 Series Security Appliances support Cisco TCP and UDP NAT traversal methods as methods complementary to existing support for the Internet Engineering Task Force (IETF) UDP wrapper mechanism for safe traversal through NAT and Port Address Translation (PAT) boundaries.

■ Cisco VPN Client security posture enforcement: Cisco PIX 500 Series Security Appliances have the ability to perform Cisco VPN Client security posture checks when a VPN connection is initiated. Capabilities include enforcing use of authorized host-based security products (such as the Cisco Security Agent [CSA]) and verifying its version number, policies, and status (enabled or disabled).

■ Cisco VPN Client blocking by operating system and type: Cisco PIX 500 Series Security Appliances can restrict different types of Cisco VPN Clients (Cisco VPN Software Client, , Cisco VPN 3002 Concentrator, and Cisco PIX security appliances) that are allowed to connect based on the type of client, operating system version installed, and Cisco VPN Client software version used. When noncompliant users attempt to connect, they can be directed to a group that specifically allows connections from noncompliant users.

6-104 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

■ Open Shortest Path First (OSPF) dynamic routing over VPN: OSPF neighbors are supported across an IPsec VPN tunnel. This allows the CSA to support dynamic routing updates across a VPN tunnel to other OSPF peers. OSPF "hello packets" are unicast and encrypted for transport down the tunnel to an identified neighbor in an RFC-compliant manner.

■ VPN hardware acceleration: Certain Cisco PIX 500 Series Security Appliance models have integrated hardware VPN acceleration capabilities. The Cisco VAC+ delivers up to 495 Mbps of DES, 3DES, or AES IPsec encryption throughput.

© 2006 Cisco Systems, Inc. Building IPsec VPNs 6-105

Continue reading here: VPN Product Placement

Was this article helpful?

0 0