Cisco Cisco IOS Software Release 12.4(9)T

Página de 22
DES/3DES/AES VPN Encryption Module (AIM-VPN/SSL-1, AIM-VPN/SSL-2, and AIM-VPN/SSL-3)
  Prerequisites for the DES/3DES/AES VPN Encryption Module (AIM-VPN/SSL-1, AIM-VPN/SSL-2, and AIM-VPN/SSL-3)
2
Cisco IOS Security Configuration Guide
Prerequisites for the DES/3DES/AES VPN Encryption Module 
(AIM-VPN/SSL-1, AIM-VPN/SSL-2, and AIM-VPN/SSL-3)
Installation Preconditions
Cisco IOS software Release 12.4(9)T
Note
See 
 for AIM-VPN/SSL-1, AIM-VPN/SSL-2, and AIM-VPN/SSL-3 encryption module support 
by Cisco IOS release.
A working IP network
For more information about configuring IP, see the Cisco IOS IP configuration guides, Release 12.4, 
which may be accessed at 
Restrictions for the DES/3DES/AES VPN Encryption Module 
(AIM-VPN/SSL-1, AIM-VPN/SSL-2, and AIM-VPN/SSL-3)
Rivest, Shamir, and Adelman (RSA) encryption supports only 512, 1024, 1536, and 2048 bit keys.
To achieve maximum benefit from hardware-assisted IP Payload Compression Protocol (IPPCP), it 
is suggested that prefragmentation be disabled if IP compression with the Limpel Zif Stac (LZS) 
algorithm is enabled on IP Security (IPsec) sessions.
Hardware acceleration is supported only for clients that are connecting to an SSL VPN gateway 
using SSL2.0 or SSL3.0 protocols when the rc4-md5 encryption transform is configured on the SSL 
VPN gateway. If aes-sha1 or 3des-sha1 encryption transforms are used, those protocols are 
processed on the router by the Cisco IOS software. SSL VPN clients should be configured for 
version 1.0 of the Transport Layer Security (TLS) protocol if you are using an encryption algorithm 
other than rc4-md5.
Information About the DES/3DES/AES VPN Encryption Module 
(AIM-VPN/SSL-1, AIM-VPN/SSL-2, and AIM-VPN/SSL-3)
Before using the DES/3DES/AES VPN Encryption Module (AIM-VPN/SSL-1, AIM-VPN/SSL-2, and 
AIM-VPN/SSL-3), you should be familiar with the following concept: