Q&A
© 2010 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 5 of 11
Q. What VPN features do the platforms support?
A. The hardware-accelerated IPsec VPN feature is available on both the Cisco 870 Series and the Cisco 850
Series. Encryption algorithms DES, 3DES, and AES are supported. In addition, the Cisco 870 Series supports
Dynamic Multipoint VPN (DMVPN), Tunnel-lessGroup Encrypted Transport VPN (GET), and Easy VPN.
Q. What intrusion prevention features are supported on the platforms?
A. Cisco 870 Series routers with the Advanced IP Services feature set support the Cisco IOS Intrusion Prevention
System (IPS) feature. Cisco IOS IPS is an inline, deep-packet inspection-based feature that enables Cisco IOS
Software to effectively mitigate a wide range of network attacks. As a core facet of the Cisco Self-Defending
Network, Cisco IOS IPS enables the network to defend itself with the intelligence to accurately identify, classify,
and stop or block malicious or damaging traffic in real time. For more information on Cisco IOS IPS support, visit
http://www.cisco.com/en/US/products/ps6634/products_ios_protocol_group_home.html. The Cisco 850 Series
does not support the IPS features.
Q. Do the platforms support transparent Cisco IOS Firewall?
A. Yes. Transparent Cisco IOS Firewall is supported only on the Cisco 870 Series routers.
Q. Do the platforms support Zone Based Cisco IOS Firewall?
A. Zone-Based Cisco IOS Firewall is supported only on the Cisco 870 Series routers.
Q. Do the Cisco 870 Series and Cisco 850 Series support 802.1x on the switch ports (that is, Fast Ethernet
0-3)?
A. Starting with Cisco IOS Software Release 12.4(11)T, the Cisco 870 series supports 802.1x VLAN Assignment,
802.1x Guest VLAN, 802.1x Spouse & Kids (on the SVI), and 802.1x with VVID.
For more information on 802.1x support, visit
http://www.cisco.com/en/US/prod/collateral/routers/ps5853/prod_white_paper0900aecd806c6d65.html and
http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124newft/124t/124t11/ht_8021x.htm
The Cisco 850 Series does not support 802.1x on the switch ports.
Hardware Features
Q. What does the integrated 10/100 switch provide?
A. All models have an integrated 10/100 four-port switch. The Cisco 870 Series provide a managed switch with up
to four 802.1Q VLANs in addition to a default VLAN; each switch port could be assigned to a different VLAN as
desired. Beside the capability to set the speed/duplex capabilities on the switch ports, switch port monitoring
(SPAN) and IGMP Snooping is also supported.
The Cisco 850 Series has a partially managed switch providing the ability to set the speed and duplex
capabilities on switch ports, the ability to shut/unshut switch ports, and SNMP management. But VLANs are
configurable only on the Cisco 870 Series and not the Cisco 850 Series.
Q. How is demilitarized zone (DMZ) functionality supported on the Cisco 870 Series?
A. On Cisco 870 Series routers, traffic separation can be achieved using VLANs.
Q. What is the USB port of the Cisco 871 Integrated Services Router used for?
A. The USB port supports holding removable security credentials. USB memory drives can also hold router
configuration information. This is not a general-purpose USB port to connect external devices to the router, and
the router does not carry drivers to support additional functions.
Q. Do the Cisco 870 Series and 850 Series support dial backup and out-of-band management?
A. The Cisco 870 Series supports both dial backup and out-of-band management on its virtual auxiliary port with an
external modem connected to it. The Cisco 876 router has an ISDN S/T port for ISDN dial backup and out-of-
band management. The Cisco 878 has an ISDN S/T port for out-of-band management only in addition to its
Comments to this Manuals