
3
Release Notes for Cisco VPN 3002 Hardware Client Release 3.5.2
78-13971-02
Release 3.5 New Software Features
Central-site VPN Concentrator Requirements
To interoperate with a VPN 3002, the VPN 3000 Series Concentrator to which it
connects must:
• Be running software version 3.0 or later. For most features new in software
version 3.5, you must be running version 3.5 software on both the VPN 3002
and on the VPN Concentrator to which it connects.
• Configure IPSec group and user names and passwords for this VPN 3002.
• For a VPN 3002 running in PAT mode, enable a method of address
assignment: DHCP, address pools, per user, or authentication server address.
• For a VPN 3002 running in Network Extension mode, use Reverse Route
Injection, a VPN Concentrator feature new in Release 3.5, or configure on
your central-site router a static route to the private network of the VPN 3002.
See Chapter 3, “Quick Configuration using the VPN 3002 Hardware Client
Manager,” in the VPN 3002 Hardware Client Getting Started manual for
step-by-step Quick Configuration instructions.
Release 3.5 New Software Features
The following sections describe software features new in Release 3.5.
IPSec over TCP
IPSec over TCP encapsulates encrypted data traffic within TCP packets. This
feature enables the VPN 3002 to operate in an environment in which standard
Encapsulating Security Protocol (ESP, Protocol 50) or Internet Key Exchange
(IKE, UDP 500) cannot function, or can function only with modification to
existing firewall rules. IPSec over TCP encapsulates both the IKE and IPSec
protocols within a TCP packet, and enables secure tunneling through both NAT
and PAT devices and firewalls.
Note This feature does not work with proxy-based firewalls.
The VPN 3002 Hardware Client, which supports one tunnel at a time, can connect
using either standard IPSec, IPSec over TCP, or IPSec over UDP.
Komentáře k této Příručce