Guest

CiscoWorks CiscoView

CiscoView Device Manager Version 1.1 for the Cisco Catalyst 6500 Series IPSec

DATA SHEET

The CiscoView Device Manager Version 1.1 for the Cisco® Catalyst® 6500 Series IPSec VPN Services Module (VPNSM) is a device-management software application that helps users to easily configure IP Security (IPSec) VPN services on their VPNSM. A task-based tool that allows users to take advantage of the versatility of their VPNSM, it offers configuration wizards based on best practices in tasks such as setting up basic site-to-site VPN links. CiscoView Device Manager is a free embedded manager that resides in the Catalyst 6500 Series Switch flash memory.

KEY FEATURES AND BENEFITS

The Next Generation of Device-Embedded Solutions

The Cisco Catalyst 6500 Series IPSec VPN Services Module is a feature-rich VPN solution from Cisco Systems®. Managing this module requires a high level of awareness of the command-line interface (CLI) for users to take advantage of the VPNSM's versatility. Typical challenges faced by users include creating basic site-to-site VPN tunnels, configuring crypto maps, and configuring the remote-access VPN server.
The CiscoView Device Manager 1.1 for the VPNSM manages most of the IPSec VPNSM features and helps users to accomplish these tasks with ease. CiscoView Device Manager offers the following features:

• Customizable initial setup wizards

• Comprehensive configuration of IPSec VPN services using a single tool

CiscoView Device Manager 1.1 for the VPNSM (Figure 1) offers the following broad capabilities:

• Basic site-to-site VPN configuration

• Dynamic crypto map configuration

• Remote access server configuration

• VPN status and statistics

Figure 1. CiscoView Device Manager 1.1 for the VPNSM Home Page

Basic VPN configuration entails configuring the following through CiscoView Device Manager:

• Crypto Maps

• Transform sets

• Internet Key Exchange (IKE) policies (using only pre-shared keys)

• Pre-shared keys

• ACLs

CiscoView Device Manager users will also be able to configure the following advanced features:

• Remote access server configuration

• Dynamic crypto maps

• Dead Peer Detection (DPD)

• Reverse Route Injection (RRI) configuration

• Hot Standby Router Protocol (HSRP)

• Generic routing encapsulation (GRE) tunnel and tunnel protection

Figure 2 shows statistics that consist of the result of all "show crypto" commands.

Figure 2. IPSec VPN Statistics

Remote Access Server Configuration

In remote access VPN, a remote device contacts a central-site router or concentrator, and provides authentication credentials. If the credentials are valid, the central site "pushes" configuration data securely to the remote device and VPN is established.
CiscoView Device Manager supports the configuration policy lookup using authentication, authorization, and accounting (AAA). It can also help users to configure and edit group policy information for individual groups. CiscoView Device Manager supports the configuration of Apply mode and Xauth. Figure 3 shows the setup of VPN crypto configurations.

Figure 3. Remote Access VPN Configuration

Crypto Maps

CiscoView Device Manager allows users to create crypto maps, thus helping them to set up policies for encrypting connections. It also helps users to tie crypto maps to transform sets, ACLs, and peer information. CiscoView Device Manager can manage all the algorithms supported by the IPSec VPNSM. CiscoView Device Manager also supports the creation of dynamic crypto maps where some parameters are negotiated during the VPN tunnel setup (Figure 4).

Figure 4. Crypto Maps

IKE Policies

CiscoView Device Manager can configure IKE policies for security association negotiation. CiscoView Device Manager only supports IKE policies with pre-shared keys.

Transform Sets

CiscoView Device Manager can configure transform sets, which decide what algorithm to use for tunnel or transport-mode setup. This involves algorithms for encryption and data integrity.

Pre-Shared Keys

CiscoView Device Manager allows users to effectively manage their pre-shared keys by enabling them to configure, modify, and delete them.

Access Control Lists

CiscoView Device Manager supports the creation of named and numbered ACLs for all protocols supported by the VPNSM such as IP, TCP, UDP, GRE, Interior Gateway Routing Protocol (IGRP), and Internet Control Message Protocol (ICMP). Besides enabling users to group ACLs according to their usage, CiscoView Device Manager also helps them to carry out basic semantic checks of ACLs.

Dead Peer Detection

CiscoView Device Manager supports the configuration of the frequency of DPD keepalives which are sent to make sure the VPN peer is available in site-to-site VPNs.

Reverse Route Injection Configuration

CiscoView Device Manager supports the enabling of Reverse Route Injection (RRI) in crypto maps, which is used to populate the routing table of an internal router running Open Shortest Path First (OSPF) protocol or Routing Information Protocol (RIP) for remote VPN clients or LAN-to-LAN sessions.

Hot Standby Routing Protocol

By supporting Hot Standby Routing Protocol (HSRP), CiscoView Device Manager helps to achieve near-100 percent network uptime through IP network redundancy, by helping ensure that user traffic immediately and transparently recovers from first-hop failures in network-edge devices or access circuits. CiscoView Device Manager supports the configuration of HSRP groups on crypto maps and interfaces, setting up alternate router IP addresses and configuration of priorities.

GRE Tunnel and Tunnel Protection

CiscoView Device Manager supports configuration of one end of a GRE tunnel, creation of a mirror configuration for the VPN peer, and enabling VPN on GRE tunnel (Start encryption) (Figure 5).

Figure 5. Remote Access VPN Setup

Table 1 lists the system specifications for the CiscoView Device Manager 1.1 for the VPNSM, and Table 2 lists the Cisco IOS® Software releases that are supported.

Table 1. System Specifications for CiscoView Device Manager 1.1 for the VPNSM

Parameter

Specifications

Chassis Supported

Cisco Catalyst 6503, Catalyst 6503-E, Catalyst 6506, Catalyst 6506-E, Catalyst 6509, Catalyst 6509-E, Catalyst 6509 NEB, Catalyst 6509-NEB-A, Catalyst 6513

Supervisor-Engine Cards Supported

Cisco Catalyst supervisor engines 2 and 720

Modules Supported

VPNSM

Client Operating System

Windows 2000 Professional with Service Pack 2, 3, and 4, Windows XP Service Pack 1, Solaris 2.8 and 2.9

Browsers

Internet Explorer 6.0 Service Pack 1 on Windows, Netscape Navigator 7.0 on Solaris, Netscape Navigator 7.1 on Windows, Mozilla Firefox 1.0 on Windows

Java Plug-In

Java plug-in 1.4.2_06

Memory Requirements

Minimum 3 MB of free flash memory on the supervisor engine

Recommended Connection Speed

56 Kbps or higher

Table 2. Cisco IOS Software Release Support

Module

Cisco IOS Software Release

Software Release for Services Module

Cisco Catalyst 6500 Series Supervisor Engine 2 with Multilayer Switch Feature Card (MSFC) 1 or 2

12.1(13)E, 12.1(19)E, 12.1(20)E, 12.1(22)E, 12.1(23)E, 12.1(26)E, 12.2(14)SY, 12.2(17d)SXB, 12.2(18)SXD

-

Catalyst 6500 Series Supervisor Engine 720

12.2(14)SX, 12.2(17a)SX,12.2(17d)SXB, 12.2(18)SXD

-

IPSec VPN

12.2(18)SXD, 12.2(18)SXD1

-

Note: CiscoView Device Manager 1.1 for the Cisco Catalyst 6500 Series Switch supports native-mode deployments only.

ORDERING INFORMATION

CiscoView Device Manager for the Cisco Catalyst 6500 Series IPSec VPN Services Module is part of the CiscoView Device Manager suite of device-embedded management applications. These management solutions are available as downloadable files from Cisco.com or as part of the purchase of a Cisco Catalyst 6500 Series Switch through regular Cisco sales and distribution channels worldwide.
To place an order, visit the Cisco Ordering Home Page.

SERVICE AND SUPPORT

Cisco offers a wide range of services programs to accelerate customer success. These innovative services programs are delivered through a unique combination of people, processes, tools, and partners, resulting in high levels of customer satisfaction. Cisco services help you to protect your network investment, optimize network operations, and prepare the network for new applications to extend network intelligence and the power of your business. For more information about Cisco services, see Cisco Technical Support Services or Cisco Advanced Services.

FOR MORE INFORMATION

For more information about the CiscoView Device Manager applications, visit http://www.cisco.com/go/cvdm or contact your local Cisco account representative or send an e-mail to the Product Marketing group at ciscoworks@cisco.com.
Text Box:  Corporate HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:   408 526-4000    800 553-NETS (6387)Fax: 408 526-4100    European HeadquartersCisco Systems International BVHaarlerbergparkHaarlerbergweg 13-191101 CH AmsterdamThe Netherlandswww-europe.cisco.comTel:  31 0 20 357 1000Fax:    31 0 20 357 1100    Americas HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:    408 526-7660Fax:    408 527-0883    Asia Pacific HeadquartersCisco Systems, Inc.168 Robinson Road#28-01 Capital TowerSingapore 068912www.cisco.comTel: +65 6317 7777Fax: +65 6317 7799Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed onthe Cisco Website at www.cisco.com/go/offices.Argentina · Australia · Austria · Belgium · Brazil · Bulgaria · Canada · Chile · China PRC · Colombia · Costa Rica · Croatia · Cyprus Czech Republic · Denmark · Dubai, UAE · Finland · France · Germany · Greece · Hong Kong SAR · Hungary · India · Indonesia · Ireland · Israel Italy · Japan · Korea · Luxembourg · Malaysia · Mexico · The Netherlands · New Zealand · Norway · Peru · Philippines · Poland · Portugal Puerto Rico · Romania · Russia · Saudi Arabia · Scotland · Singapore · Slovakia · Slovenia · South Africa · Spain · Sweden · Switzerland · Taiwan Thailand · Turkey · Ukraine · United Kingdom · United States · Venezuela · Vietnam · ZimbabweCopyright  2005 Cisco Systems, Inc. All rights reserved. CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Empowering the Internet Generation, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo, Networking Academy, Network Registrar, Packet, PIX, Post-Routing, Pre-Routing, ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet, StrataView Plus, TeleRouter, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0502R)   205224.bt_ETMG_LF_4.05Printed in the USA Text Box:  Corporate HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:    408 526-4000    800 553-NETS (6387)Fax: 408 526-4100    European HeadquartersCisco Systems International BVHaarlerbergparkHaarlerbergweg 13-191101 CH AmsterdamThe Netherlandswww-europe.cisco.comTel:  31 0 20 357 1000Fax:    31 0 20 357 1100    Americas HeadquartersCisco Systems, Inc.170 West Tasman DriveSan Jose, CA 95134-1706USAwww.cisco.comTel:    408 526-7660Fax:    408 527-0883    Asia Pacific HeadquartersCisco Systems, Inc.168 Robinson Road#28-01 Capital TowerSingapore 068912www.cisco.comTel: +65 6317 7777Fax: +65 6317 7799Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed onthe Cisco Website at www.cisco.com/go/offices.Argentina · Australia · Austria · Belgium · Brazil · Bulgaria · Canada · Chile · China PRC · Colombia · Costa Rica · Croatia · Cyprus Czech Republic · Denmark · Dubai, UAE · Finland · France · Germany · Greece · Hong Kong SAR · Hungary · India · Indonesia · Ireland · Israel Italy · Japan · Korea · Luxembourg · Malaysia · Mexico · The Netherlands · New Zealand · Norway · Peru · Philippines · Poland · Portugal Puerto Rico · Romania · Russia · Saudi Arabia · Scotland · Singapore · Slovakia · Slovenia · South Africa · Spain · Sweden · Switzerland · Taiwan Thailand · Turkey · Ukraine · United Kingdom · United States · Venezuela · Vietnam · ZimbabweCopyright  2005 Cisco Systems, Inc. All rights reserved. CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Empowering the Internet Generation, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink, Internet Quotient, IOS, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo, Networking Academy, Network Registrar, Packet, PIX, Post-Routing, Pre-Routing, ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet, StrataView Plus, TeleRouter, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0502R)   205224.bt_ETMG_LF_4.05Printed in the USA