Specifications
Americas Headquarters:
Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA
Configuring Security Features
Cisco 3900 series, 2900 series, and 1900 series integrated services routers (ISRs) provide the following
security features:
• Configuring the Cryptographic Engine Accelerator, page 1
• Configuring SSL VPN, page 2
• Authentication, Authorization, and Accounting, page 2
• Configuring AutoSecure, page 3
• Configuring Access Lists, page 3
• Configuring Cisco IOS Firewall, page 4
• Zone-Based Policy Firewall, page 5
• Configuring Cisco IOS IPS, page 5
• Content Filtering, page 5
• Configuring VPN, page 6
• Configuring Dynamic Multipoint VPN, page 23
• Configuring Group Encrypted Transport VPN, page 24
Configuring the Cryptographic Engine Accelerator
Services Performance Engine 200 and Services Performance Engine 250 have an onboard cryptographic
engine accelerator that is shared between SSLVPN and IPSec protocols.
By default, acceleration of SSL is disabled so IPSec performance is maximized. To set up a router as an
SSLVPN gateway, enable hardware acceleration for SSLVPN with the crypto engine accelerator
bandwidth-allocation ssl fair command from global configuration mode. Issue the reload command.