EN ACT ACT 1 PWR SYS RDY Cisco 71 Series VPN Routers Product Overview The Cisco 71 Series VPN Router is a high-end, integrated VPN solution melding high-speed, industry-leading routing with a comprehensive suite of advanced site-to-site VPN services. The Cisco 71 Series VPN Router integrates key features of VPNs-tunneling, data encryption, security, firewall, quality of service (QoS), and service-level validation-to deliver selfhealing, self defending VPN platforms that better and more cost-effectively accommodate remote-office and extranet connectivity using public data networks. The Cisco 71 Series VPN Router offers specific hardware configurations optimized for VPN applications and network topologies. Embedded Fast Ethernet interfaces combined with highperformance routing and rich VPN services provide turnkey VPN routing solutions. The Cisco 71 Series encompasses two VPN routers, the Cisco 712 and the Cisco 714, each of which comes with Integrated Services Module (ISM) encryption hardware accelerators. The Cisco 712 is the entry-level Cisco 71 Series VPN Router, integrating high-performance, industry-leading routing with scalable VPN security and bandwidth management to provide cost-effective, comprehensive VPN solutions for larger branch offices and headquarters. The Cisco 712 comes with dual Fast Ethernet LAN interfaces and an integrated four port serial WAN interface. The Cisco 714 series provides superior routing and VPN services performance for the most demanding VPN deployments, as well as dual Fast Ethernet LAN interfaces and dual power supplies. Features common to the Cisco 712 and 714 include: Dual autosensing 1/1BaseT Fast Ethernet ports Integrated Services Module (ISM) for hardware-based VPN services acceleration, such as high-speed IPSec or MPPE encryption One expansion slot for interface extensibility, utilizing over 3 Cisco 7xxx port adapters that enable LAN/WAN interface customization for specific site requirements. This expansion slot can also be utilized to increase VPN encryption scalability for the Cisco 714 with inclusion of the Integrated Services Adapter (ISA). 128 MB system memory for reliable, high-speed VPN services delivery-expandable to 256 MB 64 MB packet memory for QoS buffer depth and long-delay networks 48 MB Flash disk for storing Cisco IOS images---expandable to dual 128 MB Flash disks Dual PCMCIA card slots for loading and storing Cisco IOS configuration files from Flash disk or Flash memory cards Low profile, two rack unit design for rack space conservation Cisco IOS IPSec with VPN and quality of service (QoS) features included Figure 18-18: Cisco 712 - Rear View PC Card ESD receptacle slots (covered) Modular port adapter Service module 2266 5 SLOT SLOT 1 I RCVR XMTR RCLK FERF RL FE / FE / 1 AUX TX E3 RX CONS AIS OOF LL 712 - T3 2 Fixed WAN port Fixed LAN ports Console and auxiliary ports Power supply Grounding receptacles Visit Cisco Connection Online at www.cisco.com 1
EN RX EN RX ACT ACT 1 PWR SYS RDY AC OK DC OK OTF AC OK DC OK OTF 714-2AE3 1-24Vac 5/6Hz 5-2.5A 525W Figure 18-19: Cisco 714 - Rear View ESD receptacle Modular port adapter Service module 5 SLOT SLOT 1 29421 I CEL CAR ALM E3 TX RX TX FE / FE CEL CAR ALM / 1 AUX E3 RX CONS 2 Fixed WAN port PC Card Power supply slots (covered) Fixed LAN ports Console and auxiliary ports Grounding receptacles Table 18-65: Product Features for Cisco 71 Series Feature Cisco 712 Cisco 714 Embedded processor RISC MIPS RISC MIPS Throughput of VPN services, like bandwidth 5 Mbps Up to 14 Mbps management and firewall Encryption throughput with single VPN 5 Mbps 9 Mbps accelerator card Encryption throughput with dual VPN accelerator Not supported 14 Mbps card Packet throughput 175 Kpps 3 Kpps 64 MB packet, 128 MB system memory included Yes Yes System memory expandable to 256 MB Yes Yes Embedded dual 1/1BaseT Fast Ethernet interfaces Yes Yes 71 Series models 712-4T1/VPN: dual Fast Ethernet, 4T1/E1 serial, ISM encryption card, IPSec DES and QoS 712-4T1/VPN/K9: dual Fast Ethernet, 4T1/E1 serial, ISM encryption card, IPSec 3DES and QoS Compact, 2 rack unit design Yes Yes Cisco IOS IPSec and QoS included Yes Yes 714-2FE/VPN: dual Fast Ethernet, ISM encryption card, IPSec DES and QoS 714-2FE/VPN/K9: dual Fast Ethernet, ISM encryption card, IPSec 3DES and QoS 714-2FE/2VPN/K8: dual Fast Ethernet, ISM and ISA encryption cards, IPSec DES and QoS 714-2FE/2VPN/K9: dual Fast Ethernet, ISM and ISA encryption cards, IPSec 3DES and QoS Options for Cisco 71 Series Key Features and Benefits The Cisco 71 series provides the following benefits: Reduce WAN Costs, Increase WAN Flexibility 2 Cisco Product Catalog, July, 22
Specifications By using Internet transport, site-to-site VPNs cut recurring WAN costs by 5% or more compared with traditional WAN technologies such as Frame Relay. And unlike Frame Relay, VPNs can be easily and quickly extended to new locations and extranet business partners. Encryption performance greater than full duplex DS-3 line rate Utilizing ISM and ISA hardware encryption acceleration, the Cisco 71 Series VPN Router can support up to 3 simultaneous IPSec tunneling sessions with 3DES IPSec encryption performance up to 14 Mbps, thus enabling scalable site-to-site VPN connectivity to remote offices and extranet partners. Support for diverse networking environments IPSec is a unicast, IP-only protocol. The Cisco 71 Series VPN Router utilizes Cisco IOS features to accommodate multicast and multiprotocol traffic, as well as routing across the VPN, thus delivering flexible solutions for the most diverse site-to-site VPN environments. The rich routing functionality inherent to the Cisco 71 Series also simplifies VPN deployment by eliminating burdensome static routes associated with VPN appliances. Comprehensive VPN features Support for all features key to VPNs-IPSec data encryption, wide array of tunneling protocols, broad certificate authority support for PKI, as well as advanced features like certificate auto-enrollment. Deployment flexibility: dedicated VPN gateway or single-box network solution Like all Cisco VPN Routers, the Cisco 71 Series can serve as a dedicated VPN gateway or an integrated, single-box VPN router solution. For network environments requiring a single-box solution, the Cisco 71 Series offers integrated content-aware QoS to ensure reliability of latency-sensitive applications, ICSA certified stateful firewall and intrusion detection for perimeter security, service-level validation to monitor network performance, and a wide variety of LAN and WAN interfaces for diverse connectivity requirements. Built-in VPN resiliency Ensuring reliable, resilient network connectivity requires integration at many levels. The Cisco 71 Series VPN Router delivers VPN resiliency natively through its support of full Layer 3 routing, such as EIGRP and OSPF, over IPSec VPNs, as well as through the hot-swappable router protocol (HSRP) and power supply, fan, and network interface redundancy. All-encompassing site-to-site VPN management framework Managing multiple VPN devices over multiple sites requires not only robust VPN configuration management and monitoring capabilities, but also device inventory and version management features. The Cisco 71 Series VPN Router is supported by key Cisco VPN configuration and monitoring applications like VPN Management Solution (VMS) and the web-based VPN Device Manager (VDM). Hardware Table 18-66: Technical Specifications for Cisco 71 Series Description Cisco 712 Cisco 714 Processor RISC MIPS 5 Series RISC MIPS 7 Series Supported Interfaces Embedded dual 1/1BaseT Fast Autosensing, RJ-45 interface Autosensing, RJ-45 interface Ethernet interfaces Embedded WAN interface by model 712-4T1: 4T1/E1 serial with 5-in-1 serial interface supporting EIA/TIA-232, EIA/TIA-449, EIA-53, X.21, and V.35 None Physical interfaces EIA/TIA-232, EIA/TIA-449, X.21, V.35, EIA-53 None Visit Cisco Connection Online at www.cisco.com 3
Description Cisco 712 Cisco 714 Supported network port and service adapters Synchronous Serial HSSI ISDN BRI Integrated Services Adapter (ISA) Console and auxiliary ports 1 of each, RJ-45 interface 1 of each, RJ-45 interface Memory Default 64 MB packet, 128 MB system memory, SDRAM, included 64 MB packet, 128 MB system memory, SDRAM, included Expansion options Expandable to 256 MB, optional Expandable to 256 MB, optional Flash memory 48 MB Flash disk included 48 MB Flash disk included PCMCIA slots for Flash memory 2 2 Table 18-67: Power Requirements for Cisco 71 Series Description Cisco 712 Cisco 714 AC power supply Single AC, included Dual AC, included Input voltage 1 to 24 VAC Max. input 525 Watt AC Current 5 2.5 A Frequency 5/6 Hz Power Factor.8 to.95 Cables 8 AWG2 three-wire cable, with a three-lead IEC-32 receptacle on the power supply end, and a countrydependent plug on the power source end Table 18-68: Physical and Environmental Specifications for Cisco 71 Series Description Cisco 712 Cisco 714 Airflow ~12 cfm3 Operating Temperature 32 to 14 F ( to 4 C) Storage Temperature 4 to 149 F ( 2 to 65 C) Humidity (noncondensing) 1 to 9% Dimensions (H x W x D) 3.5 x 17.5 x 18.25 in. (8.89 x 44.45 x 46.36 cm) Weight ~ 32 lb (14.5 kg) Table 18-69: Regulatory Approvals for Cisco 71 Series Description Cisco 712 Cisco 714 Agency Approvals Safety UL195, CSA C22.2 No.95, IEC 95, EN695, AS/ NZS 326, TS1 Regulatory Compliance CE marking EMC FCC Part 15 (CFR 47) Class A, ICES-3 Class A, EN5522 Class B, CISPR22 Class B, AS/NZS 3548 Class B, VCCI Class B Telecom CTR3, CTR4, CTR12, CTR13, CTR 24, FCC Part 68, CS 3, Green Book, G.73, TS16, TS16, TS14, TS38 4 Cisco Product Catalog, July, 22
Description Cisco 712 Cisco 714 Network homologation Europe: CTR2,CTR3 Canada: CS-3 Unites States: FCC Part 68 Japan: Jate NTT Australia/New Zealand: TS13/TS-31 Hong Kong: CR22 Software The Cisco 71 Series supports a variety of Cisco IOS feature sets. Basic routing with IPSec, full QoS features, IPSec Management Information Base (MIB) and VPN tunneling are included as part of each Cisco 71 Series model. Optional features illustrated in Table 2, such as Enterprise multiprotocol support and Cisco IOS Firewall Feature Set, may be purchased as a factory upgrade with the router or as a spare to tailor router capabilities for specific site requirements. All feature sets include L2TP, L2F, and GRE for VPN tunneling, advanced bandwidth management features, full Layer 3 routing, NAT, DHCP, LAN/WAN interface, AAA, and NetFlow accounting support. Enterprise feature sets provide multiprotocol support for IPX, AppleTalk, IBM/SNA, and other protocols. For VPN deployment, feature sets with IPSec encryption and Cisco IOS Firewall Feature Set support are recommended. Non-encryption and 56-bit IPSec feature sets are offered for compliance with import/export regulations. Table 18-7: VPN Router Software Feature Sets for Cisco 71 Series IP Multi- Protocol Full Layer 3 Routing VPN Tunneling Advanced Bandwidth Mgmt 56-Bit IPSec 168-Bit IPSec Firewall IP/IPSec 56 Yes Yes Yes Yes Yes IP/IPSec 3DES Yes Yes Yes Yes Yes Yes IP/Firewall Yes Yes Yes Yes Yes IP/Firewall/IPSec 56 Yes Yes Yes Yes Yes Yes IP/ Firewall/IPSec 3DES Yes Yes Yes Yes Yes Yes Yes Enterprise/IPSec 56 Yes Yes Yes Yes Yes Yes Enterprise/IPSec 3DES Yes Yes Yes Yes Yes Yes Yes Enterprise/Firewall Yes Yes Yes Yes Yes Yes Enterprise/ Firewall/IPSec 56 Yes Yes Yes Yes Yes Yes Yes Enterprise/ Firewall/IPSec 3DES Yes Yes Yes Yes Yes Yes Yes Yes Ordering Information Product Part Numbers All part descriptions and part numbers for Cisco products can be accessed using the online Cisco Pricing Tool at http://www.cisco.com/cgi-bin/order/pricing_root.pl Configuration Guidelines Each Cisco 71 Series VPN Router includes a central processing unit (CPU), dual Fast Ethernet interfaces, ISM encryption card, system and packet memory, Flash memory, power supply, and Cisco IOS IPSec in the base unit as outlined in the Product Overview section. Each model also includes one expansion slot that utilizes most single-wide Cisco 7xxx Series port and service adapters. Visit Cisco Connection Online at www.cisco.com 5
Items that are included with the base Cisco 71 Series unit but are upgradeable at the factory or as a spare include: System memory Flash memory Cisco IOS Optional items that are not included with the base Cisco 71 Series unit, but are factory configurable or orderable as a spare include: I Integrated Service Adapter for increased VPN encryption scalability Supported Cisco 7xxx single wide port adapter for LAN/WAN interface customization 6 Cisco Product Catalog, July, 22