SDM Data Sheet
SDM Data Sheet
This data sheet provides an overview of features, benefits, and product availability of the
®
Cisco Router and Security Device Manager (SDM).
®
Cisco SDM is an intuitive, Web-based device-management tool for Cisco IOS Software-based
routers. The Cisco SDM simplifies router and security configuration through smart wizards, which
help customers and Cisco partners quickly and easily deploy, configure, and monitor a Cisco
router without requiring knowledge of the command-line interface (CLI). The Cisco SDM is
supported on a wide range of Cisco routers and Cisco IOS Software releases. Refer to Table 3 for
specific model numbers supported by the Cisco SDM.
Cisco SDM smart wizards guide users step by step through router and security configuration
workflow by systematically configuring LAN, WLAN, and WAN interfaces; firewalls; intrusion
prevention systems (IPS); and IP Security (IPsec) VPNs. Cisco SDM smart wizards can
intelligently detect incorrect configurations and propose fixes, such as allowing Dynamic Host
Configuration Protocol (DHCP) traffic through a firewall if the WAN interface is DHCP-addressed.
Online help embedded within the Cisco SDM contains appropriate background information, in
addition to step-by-step procedures to help users enter correct data in the Cisco SDM. Networking
and security terms and definitions that users might encounter are included in an online glossary.
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 1 of 13
Data Sheet
For network professionals familiar with Cisco IOS Software and its security features, the Cisco
SDM offers advanced configuration tools to quickly configure and fine-tune router security
features, allowing network professionals to review the commands generated by the Cisco SDM
before delivering the configuration changes to the router.
The Cisco SDM helps administrators configure and monitor routers in remote locations using
Secure Sockets Layer (SSL) and Secure Shell (SSHv2) Protocol connections (see Figure 2). This
technology enables a secure connection over the Internet between SDM on the user’s laptop and
the router. When deployed at a branch office, a Cisco SDM-enabled router can be configured and
monitored from corporate headquarters, reducing the need for experienced network administrators
at the branch office.
Figure 2. Connecting to a Cisco SDM-Enabled Router Using SSL for Secure Remote Connectivity
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 2 of 12
Data Sheet
When invoked on an already configured router, Cisco SDM allows users to perform one-step
security audits to evaluate the strengths and weaknesses of their router configurations against
common security vulnerabilities. Administrators can fine-tune their existing router security
configurations to better suit their business needs. The Cisco SDM also can be used for day-to-day
operations such as monitoring, fault management, and troubleshooting.
Router Configuration
In addition to security configuration, Cisco SDM helps users quickly and easily configure router
services such as LAN, WLAN, and WAN interface configuration; dynamic routing; DHCP server;
QoS policy; and so on.
Using the LAN configuration wizard, users can assign IP addresses and subnet masks to Ethernet
interfaces and can enable or disable the DHCP server. Using the WAN configuration wizard, users
can configure xDSL, T1/E1, Ethernet, and ISDN interfaces for WAN and Internet access.
Additionally, for serial connections, users can implement Frame Relay, Point-to-Point Protocol
(PPP), and High-Level Data Link Control (HDLC) encapsulation. Cisco SDM also allows
configuration of static routing and common dynamic routing protocols such as Open Shortest Path
First (OSPF), Routing Information Protocol (RIP) Version 2, and Enhanced Interior Gateway
Routing Protocol (EIGRP).
QoS policies can easily be applied to any WAN or VPN tunnel interface using Cisco SDM. The
QoS policy wizard automates the Cisco architecture guidelines for QoS policies to effectively
prioritize the traffic between real-time applications (voice or video), business-critical applications
(Structured Query Language [SQL], Oracle, Citrix, routing protocols, and so on), and the rest of
network traffic (for instance, Web and e-mail traffic). Monitoring based on network based
application recognition (NBAR) in the Cisco SDM allows users to visually inspect the application
layer traffic in real time and confirms the effect of QoS policies on different classes of application
traffic.
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 3 of 12
Data Sheet
connections. For example, while troubleshooting a failed VPN connection, the Cisco SDM verifies
the router configurations and connectivity from the WAN interface layer to the IPsec Crypto Map
layer. While testing configuration and remote-peer connectivity at each layer, Cisco SDM provides
pass or fail status, possible reasons of failure, and Cisco TAC–recommended actions for recovery.
Cisco SDM monitor mode also allows users to view the number of network access attempts that
were denied by the Cisco IOS Software firewall and it provides easy access to the firewall log.
Users also can monitor detailed VPN status, such as the number of packets encrypted or
decrypted by IPsec tunnels, and Easy VPN client session details.
Table 1 describes the features that are new in Cisco SDM Version 2.5.
Feature Benefit
WAAS NM Support
● NME-WAE-502-K9 Single user interface for the initial provisioning and ongoing
● NME-WAE-522-K9 monitoring of the network module.
● NME-WAE-302-K9
● Configures WCCP on the router and IP address on the
WAE module. Registers the IP address of the WAE
module with the central WAAS manager.
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 4 of 12
Data Sheet
Feature Benefit
Advanced Encryption Service (AES), IEEE 802.1x Local Allows configuration of a rich set of wireless features on the
authentication service for EAP-FAST, SSID globalization, router.
Multiple Basic Service Set ID (BSSID), wireless root, nonroot
bridge and universal client mode, multiple encrypted VLANs,
VLAN assignment by name, Wi-Fi multimedia required
elements
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 5 of 12
Data Sheet
approved and tested by the Cisco TAC from end to end. The CLI preview mode in the Cisco SDM
allows expert users to manually validate the final configuration before it is delivered to the router.
Conclusion
The Cisco SDM is a valuable productivity-enhancing tool for network and security administrators.
Cisco partners can use the Cisco SDM for faster and easier deployment of Cisco routers for both
WAN access and network security features.
Cisco customers can use the Cisco SDM for reducing the total cost of ownership of their Cisco
routers by relying on Cisco SDM-generated configurations that are tested end to end by Cisco
engineers and approved by the Cisco TAC. Configuration checks built into Cisco SDM reduce the
instances of configuration errors.
Product Specifications
Table 2 shows primary features and benefits of the Cisco SDM. Table 3 shows product
specifications for the Cisco SDM.
Feature Benefit
Embedded Web-based ● Turns the router into a complete security and remote-access solution with its own management
Management Tool tool
● Does not require a dedicated management station
● Allows remote management from any supported desktop or laptop
SSL- and SSHv2- ● Provides for secure management across the WAN
based Secure Remote
Access
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 6 of 12
Data Sheet
Feature Benefit
At-a-Glance Router ● Offers quick graphical summary of router hardware, software, and primary router services such
Status Views as VPN, firewall, QoS, etc.
One-Step Router ● Simplifies firewall and Cisco IOS Software configuration without requiring expertise about
Lockdown security or Cisco IOS Software
Policy-Based Firewall ● Allows security administrators to easily and quickly manage ACLs and packet-inspection rules
and ACL Management through a graphical and intuitive policy table
(Firewall Policy)
IPS ● Allows easy and quick provisioning of Cisco tuned and recommended high-fidelity attack
signatures on any router interface for inbound and outbound traffic
● Allows dynamic update of new IPS signatures without impacting basic router operations
● Allows graphical customization of IPS signatures for immediate response to new worm or virus
variants
● Allows filtering of signatures and mass configuration changes (action or severity) for the selected
signatures
● Shows real-time status and error messages from IPS engine
Cisco Easy VPN ● Offers wizard-based configuration and real-time monitoring of remote-access VPN users
Server ● Provides integration with on-router or remote authentication, authorization, and accounting (AAA)
server
Role-Based Access ● Offers logical separation of router between different router administrators and users
● Provides for secure access to Cisco SDM user interface and Telnet interface specific to each
administrator’s profile
● Helps enable Cisco value-added resellers and service providers to offer a graphical, read-only
view of the CPE services to end customers
● Offers factory-default profiles:
● Administrator
● Firewall administrator
● Easy VPN client user
● Read-only user
WAN and VPN ● Reduces mean time to repair (MTTR) by taking advantage of the integration of routing, LAN,
Troubleshooting WAN, and security features on the router for detailed troubleshooting
● Takes advantage of integration of routing, LAN, WAN, and security features on the router for
detailed troubleshooting of IPsec VPNs or WAN links
● Integrates Layer 2 and above troubleshooting with Cisco TAC knowledge base of recovery
actions
QoS Policy ● Easily and effectively optimizes WAN and VPN bandwidth and application performance for
different business needs (voice and video, enterprise applications, Web, etc.)
● Three predefined categories: real time, business critical, and best effort
NBAR ● Provides real-time validation of application usage of WAN and VPN bandwidth against
predefined service policies
● Provides for traffic performance monitoring
Real-Time Monitoring ● Allows administrators to proactively manage router resources and security before they affect
and Logging mission-critical applications on the network
Digital Certificates ● Offers highly scalable and more secure solution than preshared keys
● Now easy to use and deploy with the combination of Cisco SDM, Cisco IOS Certificate Authority
Server, and Easy Secure Device Deployment (EzSDD) feature.
Real-Time Network ● Offers faster and easier analysis of router resource and network resource usage
and Router Resource ● Offers graphical charts for LAN and WAN traffic and bandwidth usage
Monitoring
Task-Based Cisco ● Provides for faster and easier configuration of security configurations—IPsec VPNs, firewall,
SDM User Interface ACLs, IPS, etc.
● Offers quick snapshot of router services configuration through dashboard view on the homepage
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 7 of 12
Data Sheet
Feature Benefit
Cisco SDM Express ● Offers quick and easy router deployment for basic WAN access configurations
Wizard-Based ● Ideal router deployment tool for nonexpert users
Deployment of Router
PC-Based SDM ● No extra Flash memory space required on router for Cisco SDM
Cisco SDM Installed ● Great tool to manage the installed base of Cisco routers
on Windows-based PC
Instead of Router
Flash Memory
Integrated Wireless ● Express Setup wizard simplifies the first-time setup of wireless interface
Management ● Advanced Web-based configuration and monitoring available
● Reduces time and skill set required to bring up wireless interfaces
● Flexibility to customize wireless configuration and security based on site-specific needs
IPS Provisioning ● Allows rapid deployment of IPS signatures specific to router model
Improvement
Application Firewall
● Advanced firewall wizards, policy views, inspection rule ● Delivers application-level control and unified threat
editors, and log views management for accelerated security solutions deployment
● Peer-to-peer (P2P) applications: BitTorrent, Kazaa, ● Provides protocol anomaly detection services
Gnutella, eDonkey ● Provides high, medium, and low security levels for firewall
● Instant Messaging: Yahoo, MSN, AOL policy settings to enable accelerated and easy deployment
● Protocol conformance: HTTP and e-mail (Simple Mail ● Low—For business environments that do not need to track
Transfer Protocol [SMTP], ESMTP, POP3, and Internet P2P and IM applications on the network or check for
Message Access Protocol [IMAP]) protocol conformance
● Medium—For business environments where security is
important and there is a need to track the use of IM and
P2P applications and check for HTTP and e-mail protocol
conformance
● High—For business environments where security is critical,
and there is a need for protocol anomaly detection services
to drop non conformant HTTP and e-mail traffic and prevent
use of P2P and IM applications
Dynamic DNS
● HTTP-based and IETF-based updates ● Enables scalable, remote management of dynamically
● Integration with existing WAN interface configuration addressed routers
wizard ● Makes it possible to run business services without
dedicated and expensive static IP addresses
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 8 of 12
Data Sheet
Feature Benefit
● Wizard-based configuration and real-time monitoring of ● Enables rapid and easy to manage deployment of secure
WebVPN features remote access connectivity for teleworkers and small office
● Persistent self-signed certificates branch routers
● IPS Security Dashboard ● Enables real-time updates on top threats from MySDN site
● Integration with Cisco IPS alert center ● Enables easier and more intelligent IPS signature selection
● IPS Signature import UI and updates based on top threats
Table 3. Product Specifications for Cisco SDM (Minimum Cisco IOS Software Releases Supported)
Supported Platforms ● Cisco Small-Business 101 Router, Cisco Small-Business 106 Router, Cisco Small-Business 107
Router:
● Cisco IOS Software Release 12.3(8)YG
● Cisco 831 Ethernet Broadband Router, Cisco 836 ADSL over ISDN Broadband Router, and Cisco
837 ADSL Broadband Router:
● Cisco IOS Software Release 12.2(13)ZH or 12.3(2)T
● Cisco 851, 856, 871, 876, 877, and 878 Integrated Services Routers:
● Cisco IOS Software Release 12.3(8)YI
● Cisco c815 router
● Cisco IOS Software Release 12.4(6)XE
● Cisco 1701 ADSL Security Access Router; Cisco 1710, 1711, and 1712 Security Access Routers;
and Cisco 1721, 1751, 1751-V, 1760, and 1760-V Modular Access Routers:
● Cisco IOS Software Release 12.2(13)ZH, 12.2(13)T3, or 12.3(1)M
● Cisco 1801, 1802, 1803, 1811, and 1812 Integrated Services Routers:
● Cisco IOS Software Release 12.3(8)YI
● Cisco 1841 Integrated Services Router:
● Cisco IOS Software Release 12.3(8)T4
● Cisco 2610XM, 2611XM, 2620XM, 2621XM, 2650XM, and 2651XM and Cisco 2691 Multiservice
Platforms:
● Cisco IOS Software Release 12.2(15)ZJ3, 12.2(11)T6, or 12.3(1)M
● Cisco 2801, 2811, 2821, and 2851 Integrated Services Routers:
● Cisco IOS Software Release 12.3(8)T4
● Cisco 3725 and 3745 Multiservice Access Routers:
● Cisco IOS Software Release 12.2(15)ZJ3, 12.2(11)T6, or 12.3(1)M
● Cisco 3825 and 3845 Integrated Services Routers:
● Cisco IOS Software Release 12.3(11)T
● Cisco 7204VXR, 7206VXR, and 7301 routers:
● Cisco IOS Software Release 12.3(2)T or 12.3(3)M; no support for B, E, and S trains
Software ● Compatible with all Cisco IOS Software feature sets for the previously listed Cisco SDM–
Compatibility supported releases of Cisco IOS Software
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 9 of 12
Data Sheet
Advanced Router ● Routing protocols: static, RIP Versions 1 and 2, OSPF, and EIGRP
Configuration ● NAT (static and dynamic)
Parameters
● ACLs
● QoS policies, NBAR
● VLANs on Cisco EtherSwitch® ports
● IP proxy Address Resolution Protocol (ARP), Internet Control Message Protocol (ICMP) redirects,
ICMP unreachable, ICMP mask reply, and directed broadcasts
● AAA local or remote configuration
Configurable ● Internet Key Exchange (IKE), digital certificates, Data Encryption Standard (DES), Triple DES
VPN Parameters (3DES), Advanced Encryption Standard (AES), and compression
● IPsec site to site
● Cisco Easy VPN Server (including DVTI support )
● Cisco Easy VPN Remote (including DVTI support )
● Generic-routing-encapsulation (GRE) tunnel
● Dynamic Multipoint VPN (DMVPN; both hub and spoke), including dynamic spoke to spoke with
redundant hubs
Supported Firewall ● Context-based access control (CBAC), Common Classification Policy Language (C3PL) zone-
Parameters based firewall, DMZ, firewall log, firewall and ACL policy view, secure management access
Supported IPS ● IPS rules for inbound or outbound traffic inspection, signature fine-tuning, signature customization,
Features and SDEE error message display
● Encrypted signature format, risk rating, automated signature update, IDCONF signature
provisioning, individual and category-based signature provisioning
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 10 of 12
Data Sheet
System Requirements
Table 4 lists the system requirements for the Cisco SDM.
Feature Description
Router Flash Memory ● Minimum of 6 MB of free Flash memory on the router for Cisco SDM files
● Minimum of 2 MB of free Flash memory on the router for Cisco SDM Express. Wireless
Management file requires additional 1.7 MB. Rest of the SDM files can be installed on PC hard
disk.
Ordering Information
Table 5 lists ordering and factory shipping options for the Cisco SDM.
Feature Description
Cisco 831 Ethernet Broadband Router, Cisco 836 ADSL ● Cisco SDM software ships by default from factory.
over ISDN Broadband Router, Cisco 837 ADSL ● SDM Express is factory installed on router Flash memory,
Broadband Router, Cisco Small-Business 100 Series and a Cisco SDM CD is bundled with the router.
Router, Cisco 850 Series Router, and Cisco 870 Series
Router
Cisco 1700 Series Modular Access Routers and Cisco ● Cisco SDM software ships by default on security bundles
2600XM Series (k9).
Cisco 1800 Series Integrated Router ( except for Cisco ● Cisco SDM software $0 configuration option (ROUTER-
1841 model with 64 MB or higher flash memory ) SDM or ROUTER-SDM-NOCF) is available on all SKUs.
● Cisco SDM Express is factory installed on router Flash
memory, and a Cisco SDM CD is bundled with the router.
Cisco 1841 (64 MB Flash memory or higher ), 2800, and ● Cisco SDM software ships by default from factory.
3800 Series Integrated Services Routers ● Cisco SDM is factory installed on router Flash memory.
Cisco 2691 Multiservice Platform and Cisco 3700 Series ● Cisco SDM software ships by default on security bundles
Multiservice Access Routers (k9).
● Cisco SDM software $0 configuration option (part number
ROUTER-SDM or ROUTER-SDM-NOCF) is available on all
SKUs.
● Cisco SDM is factory installed on router Flash memory.
Cisco 7204VXR, 7206VXR, and 7301 Routers ● Cisco SDM software ships by default on security bundles
(k9).
● Cisco SDM software $0 configuration option (part number
ROUTER-SDM or ROUTER-SDM-NOCF) is available on all
SKUs.
● Cisco SDM is factory installed on router Flash memory.
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 11 of 12
Data Sheet
For customers who want to use the AutoInstall feature in Cisco IOS Software, two US$0 SKUs are
offered: ROUTER-SDM-NOCF and ROUTER-SDM-CD-NOCF. If either of these SKUs is ordered
with a Cisco router, manufacturing loads Cisco SDM files only on the router Flash memory, and the
default startup configuration is not loaded in the router’s NVRAM.
All contents are Copyright © 1992–2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 12 of 12