IPSec Stateful failover (aka IPC sso)

Unanswered Question
Oct 26th, 2007
User Badges:

I am trying to setup IPSec Stateful

failover on a pair of VXR7204 router

running version 12.3T. I was told by

Cisco some months ago that unless IPSec

stateful will not be supported by Cisco

unless I have AIM or VAM card on the

router. This is what currently on the

VXR 7204:

VXR7204#sh crypto engine configuration

crypto engine name: Multi-VPN Using VAM2

crypto engine type: hardware

Compression: Yes

DES: Yes

3 DES: Yes

AES CBC: Yes (128,192,256)


Maximum buffer length: 4096

Maximum DH index: 5120

Maximum SA index: 5120

Maximum Flow index: 10230

Maximum RSA key size: 2048

Minimum RSA key size: 0512

crypto engine in slot: 2

platform: VPN hardware accelerator

Crypto Adjacency Counts:

Lock Count: 204555176

Unlock Count: 204555176

crypto lib version: 18.0.0

ipsec lib version: 2.0.0


Can anyone confirm that IPSec stateful

failover (aka IPC sso) will work with

VAM2 card. Thanks.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
irisrios Thu, 11/01/2007 - 11:47
User Badges:
  • Silver, 250 points or more

Yes it is supported. It is supprted on VAM, VMA2, VAM2+.


This Discussion