01-05-2016 01:10 PM - edited 03-05-2019 03:03 AM
Hi,
i am aware dmvpn does not require IPSec to run but are there any issues of running this?
Also would any one know if we can use k9 license that supports IPSec in places like Israel, Russia and turkey? At the moment router has securityk9_npe license. Is this rule only for exporting and once the box is in country can we change license to security k9?
Thanks
01-05-2016 03:53 PM
Hi Network Pro,
Without IPSEC, the tunnels will be created using GRE only, the main concern is that GRE only encapsulates the traffic, then the traffic will be clear text traffic , creating a security breach.
About the second question , I'm not totally sure, but I think the K9 license does not have restriction on any country, I've seen this license being used all around Central and South america as well most of Europa and Asia.
The router VPN has a limitation outside US, for the throughput, in order to break this limitation you can purchase a H-SEC licence.
Hope it helps,
-Randy-
01-06-2016 12:43 AM
Thanks
I cant seem to do show dmvpn - is this a code or license error or do i need to do anything to enable it ?
01-06-2016 01:23 AM
show dmvpn detail is the command you want to use if you have it configured
Regarding K9 yes you can use it in Israel we have sites there running crypto
01-06-2016 01:48 AM
i dony see any show dmvpn command at all - it says unrecognized - 15.5(3)S0c / isr4300-universalk9_npe.03.16.00c.S.155-3.S0c-ext.SP
Would you know in Russia and Turkey ?
01-06-2016 02:00 AM
Then the image unlikely supports dmvpn , you can check exactly what features your image supports on software checker below
http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp
you should be fine for Turkey with Russia though from what I remember they regulate encrypted traffic through the government so its certain types of K9 software you need to use , that's definitely the way the wireless works anyway so I assume its probably the same for routers etc
i.e
Cisco Unified Wireless Network Software Release 1.9 for Cisco 5500 Series Wireless LAN Controllers with Licensed Payload Encryption.Only Recommended for Russia Where Data DTLS Payload Encryption is Regulated by the Government. AIR-CT5500-LDPE-K9-1-9-0-0-FUS.aes |
24-JAN-2014 | 15.21 MB |
In Cart
|
To Download this software, you must have a valid service contract associated to your Cisco.com profile. | |
If you do not have a service contract you can get one through:
|
|
Once you have the service contract you must associate your service contract to your Cisco.com user ID with Profile Manager | |
To Download this software, you must Log In with your Cisco.com user ID. | |
To Download this software, you must Log In and have a valid service contract associated to your Cisco.com profile. | |
If you do not have a service contract you can get one through:
|
|
Once you have the service contract you must associate your service contract to your Cisco.com user ID with Profile Manager | |
Cisco service contract information indicates you are not authorized to download software for the following product(s): | |
5508 Wireless Controller | |
If you are downloading from the Cart, please remove software for the product(s) listed above to proceed with other software downloads. | |
Or, if you feel this message is in error, please:
|
|
Description: | Cisco Unified Wireless Network Software Release 1.9 for Cisco 5500 Series Wireless LAN Controllers with Licensed Payload Encryption.Only Recommended for Russia Where Data DTLS Payload Encryption is Regulated by the Government. |
Release: | 1.9.0.0 |
Release Date: | 24/Jan/2014 |
File Name: | AIR-CT5500-LDPE-K9-1-9-0-0-FUS.aes |
Size: | 15.21 MB (15946452 bytes) |
MD5 Checksum: | 856f7f4e0b4ba057ab8dae1f30dfc5ea |
SHA512 Checksum: |
cc73c6cb5dc7d64dfd371b4d869f0309...
|
Release Notes for 1.9.0.0 | Security Advisory |
01-06-2016 03:24 AM
would you know for ISR 4300 series also ?
01-06-2016 04:30 AM
The laws in China and Russia state that if you have cryptographic equipment in their country by right they can have access to your systems or request your keys in terms of national security theres nothing you can do , the U.S are exactly the same only the issue with China and Russia is there likely state sponsored hacking
So no matter what you put in there country's by law they can have full access no matter what so you find a lot of companies based in these countries do not share intellectuals property through there connections , China you cant even export out of unless you have a presence in the country so we use VDI so our information is not shared across there networks at all but we can still have offices there
I don't have any sites in Russia but its the same as China and there are no real definite restrictions to what cant be used but even if you don't follow them and do have a standard K9 in there as LDPE may not be available for your platform , if they want access to it and its based on there soil they can get it.
If your doing things by the book you may need an export license first
http://www.cisco.com/web/about/doing_business/legal/global_export_trade/general_export/contract_compliance.html
This where your not allowed definite to have Cisco K9
Cisco solutions and products containing 64-bit or less encryption may be delivered to most end users worldwide, except to entities or end users in the following countries: Cuba, Iran, North Korea, Sudan, and Syria.
If this has answered your query's please rate the post as it makes it easier to find the answer when other users search for same problem
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide