System information

17
Release Notes for Cisco VPN 3000 Series Concentrator, Release 3.6 Through 3.6.8.B
OL-5637-02
Open Caveats for VPN 3000 Series Concentrator
CSCdy26161
The Microsoft L2TP/IPSec client for Windows 98, Windows ME, and Windows NT does not
connect to the VPN 3000 Concentrator using digital certificates.
Workaround:
Use preshared keys.
CSCdy51295
When specifying the link rate for bandwidth management on an interface, the VPN 3000
Concentrator only permits specifying the range 1544000 - 100000000 bps.
This renders the feature difficult to use properly when the Internet link is less than T1 speed. We
should permit the full range of speeds to allow this feature to be deployed in all environments.
CSCdy51319
On the VPN 3000 Concentrator running version 3.6 code, a bandwidth management policy is created
with a reservation included, and this is applied to a group. No aggregation is applied to the group
(left at 0). Interface bandwidth management is enabled and link rate is set to 1.544 Mbs, and a
different group is applied for default users with a reservation only.
If the reservation amount is then changed on the policy the following error occurs in the log:
31 11/27/2000 15:43:48.360 SEV=4 BMGT/47 RPT=7
The Policy [ ADCUsers ] with Reservation [ 102000 bps ] being applied to Group [ ADC ] on
Interface [ 1 ] exceeds the Aggregate Reservation [ 0 bps ] configured for that group.
This error does not occur if the policy is first removed from the group, then the reservation is
changed and the policy re-applied. No users are connected at the time of the error.
The reservation should be checked against the aggregate only if aggregation is enabled.
CSCdy51333
On a VPN 3000 Concentrator running Release 3.6 code, a bandwidth management policy is created
and applied to a group reserving some portion of the link bandwidth using an aggregate reservation.
If this reservation is then changed, the previous committed bandwidth is not freed up first when
calculating whether enough bandwidth is available for use.
So, if 600 kbps is reserved from a link of 1544 kbps to start with, and this is then modified to reserve
1000 kbps, an error is generated and the modification is refused. The error shown is as follows:
83 11/27/2000 16:30:44.620 SEV=4 BMGT/31 RPT=7
Attempting to specify an Aggregate Group reservation [ 1000000 bps ] on Group [ ADC ] Interface
[ 1 ] which added to the current reservation of the interface [ 600000 bps ] exceeds the link rate [
1544000 bps ] to which it is being applied.
No bandwidth is reserved by any other policy.
Workaround:
Remove the aggregate reservation from the group first, and then to apply the new setting.
CSCdy55175
When a customer who is using the NT domain for user authentication and has the group name that
is defined in the Concentrator the same as the user name in the NT domain server, the VPN Client
can no longer connect to the Concentrator after upgrading the Concentrator to Release 3.6.1.