CISCO2911-SEC/K9 vs CISCO2911/K9 (VPN Related)

toronto1

Junior Member
May 10, 2012
2
0
0
What's the difference between CISCO2911-SEC/K9 and CISCO2911/K9?

I know that CISCO2911-SEC/K9 supports 225 simultaneous IPsec tunnels and has to be upgraded to CISCO2911-HSEC/K9 to support more than 225 tunnels.

But what's the limit on CISCO2911/K9 with regards to simultaneous IPsec tunnels?
 

toronto1

Junior Member
May 10, 2012
2
0
0
Oh! so CISCO2911/K9 doesn't support IPsec VPN? It's interesting that all the retailers of these ISR routers claim that the no SEC versions support IPsec VPN, they even advertise it on their websites. Very confusing ...

Thanks for your help.
 

imagoon

Diamond Member
Feb 19, 2003
5,199
0
0
Oh! so CISCO2911/K9 doesn't support IPsec VPN? It's interesting that all the retailers of these ISR routers claim that the no SEC versions support IPsec VPN, they even advertise it on their websites. Very confusing ...

Thanks for your help.

Right out of the pdf attached to the link:

Security Technology Package License

Standard IP Security (IPSec), Group Encrypted Transport VPN, Dynamic Multipoint VPN
(DMVPN), Easy VPN and Enhanced Easy VPN, Virtual Tunnel Interface (VTI), Multi-Virtual
Route Forwarding (VRF) Customer Edge (CE) (IPSec, firewall, and IPS), IPSec high
availability, Cisco IOS Zone-Based Firewall, advanced application inspection and control,
firewall for secure unified communications, VRF-aware firewall, firewall high availability,
transparent firewall, Cisco IOS IPS, transparent IPS, VRF-aware IPS, secure provisioning and
digital certificates, and Cisco IOS Certificate Server and Client

That also doesn't get you everything either.

SSL is extra etc


None (available in base image)

Authentication, authorization, and accounting (AAA), NetFlow, Network-Based Application
Recognition (NBAR), access control lists (ACLs), Cisco IOS Flexible Packet Matching (FPM),
802.1x, and Cisco IOS Network Foundation Protection

The routers are software upgradable so some places will say it has it and they are technically right because it takes a license code to flip to "SEC." These are not like the IOS 1841's / 3750G's that just need an updated IOS to add features.