Cisco Catalyst 6500 Series Installation Manual page 91

Switch module
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Chapter 1
Product Overview
IPSec VPN Acceleration Services Module (WS-SVC-IPSEC-1)
When you configure a VPN on the Cisco routers, a packet is sent to a routed
interface that is associated with an IP address. If the interface has an attached
crypto map, the software checks that the packet is on an access control list (ACL)
specified by the crypto map. If a match occurs, the packet is transformed
(encrypted) before it is routed to the appropriate IPSec peer; otherwise, the packet
is routed in the clear (unencrypted) state.
When you configure the VPN module, the same cryptographic operations are
performed as on Cisco routers. The VPN module's implementation of VPN is
generally the same as on Cisco routers other than the use of interface VLANs and
some configuration guidelines specific to the VPN module.
For detailed information on Cisco IOS IPSec cryptographic operations and
Note
policies, refer to the "IP Security and Encryption" section of the Cisco IOS
Security Configuration Guide, Release 12.2.
When you configure the VPN module on the Catalyst 6500 series switch, you
ensure that all packets coming from or going to the Internet pass through the VPN
module. The VPN module has an extensive set of policies that validate a packet
before the packet is sent onto the local (trusted) LAN. The VPN module can use
multiple Fast Ethernet or Gigabit Ethernet ports on other Catalyst 6500 series
modules to connect to the Internet through WAN routers. Packets received from
the WAN routers pass through the VPN module for IPSec processing.
On the local LAN side, traffic between the LAN ports can be routed or bridged on
multiple Fast Ethernet or Gigabit Ethernet ports. Because the local LAN traffic is
not encrypted or decrypted, it does not pass though the VPN module.
The VPN module does not maintain routing information, route, or change the
MAC header of a packet (except for the VLAN ID from one VLAN to another).
The front panel LED on the IPSec VPN Acceleration Services Module is
described in
Table
1-15.
Catalyst 6500 Series Switch Module Installation Guide
1-67
78-15725-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents