Cisco ISM-VPN-29
3DES/AES/SUITE-B VPN Encryption module
Product Highlights
What's Included
As branch offices demand more encrypted traffic for site-to-site VPNs, remote access, and cloud connectivity, the onboard crypto capabilities of your Cisco ISR G2 router can become a bottleneck. The Cisco ISM-VPN-29 solves this by delivering dedicated, hardware-accelerated VPN encryption for the Cisco 2900 Series Integrated Services Routers Generation 2 (ISR G2).
The ISM-VPN-29 is a VPN Internal Service Module equipped with a multicore processor that operates independently of the host router's CPU. This offload architecture ensures maximum concurrent VPN performance while preserving router resources for other business-critical services such as voice, WAN optimization, and application-aware routing. The module supports 3DES, AES (including AES-GCM in 128-, 192-, and 256-bit key lengths), and NSA-regulated Suite B cryptographic algorithms — providing strong data authentication, confidentiality, and anti-replay services.
Installing directly into the router's internal ISM slot, the ISM-VPN-29 requires no external rack space and leaves EHWIC and SM slots available for additional network modules. Whether you're scaling DMVPN tunnels across dozens of branch sites or securing remote worker access with IPsec VPN, this encryption module delivers up to three times better IPsec VPN performance compared to software-only encryption on the same platform. It's a cost-effective upgrade path for organizations that need to maximize their existing Cisco 2900 Series investment.
Features & Benefits
Hardware-Accelerated VPN Encryption
The ISM-VPN-29 features a dedicated multicore processor that handles all VPN encryption and decryption independently of the host router's CPU. This offload architecture prevents encrypted traffic from consuming router resources needed for routing, QoS, and other services — enabling your ISR G2 to deliver full-capacity encrypted throughput without compromising other branch functions.
Next-Generation Cryptography Standards
Supporting DES, 3DES, AES-CBC, and AES-GCM (128-, 192-, and 256-bit), along with MD5, SHA-1, and SHA-2 hashing algorithms, the ISM-VPN-29 covers the full spectrum of IPsec encryption requirements. It also supports NSA-regulated Suite B cryptography with RSA and ECDSA authentication, ensuring compliance with the most stringent government and enterprise security mandates.
Internal Slot-Saving Design
The ISM-VPN-29 installs into the dedicated internal ISM slot inside the Cisco 2900 Series chassis. This compact plug-in module design means you don't sacrifice any EHWIC, SM, or NME slots — leaving those available for WAN interfaces, voice DSPs, or service modules. At just 10W typical power consumption, it adds negligible load to the router's power budget.
Scalable Branch VPN Performance
The module delivers hardware-based IPsec encryption throughput that scales with the host platform — from 145 Mbps (IMIX) on the Cisco 2901 up to 385 Mbps (IMIX) on the Cisco 2951. This enables organizations to scale their encrypted WAN capacity as bandwidth demands grow, without replacing the entire router platform.
Deployment Scenarios
Multi-Site IPsec VPN with DMVPN
Organizations operating dozens or hundreds of branch offices connected via DMVPN hub-and-spoke or spoke-to-spoke topologies benefit from the ISM-VPN-29's hardware crypto offload. The module ensures that the ISR G2 router can sustain high tunnel counts and encrypted throughput without degrading routing or application performance at the branch.
Secure Remote Worker Access
For enterprises supporting remote and mobile workers connecting back to the corporate network via IPsec or SSL VPN, the ISM-VPN-29 increases the number of concurrent encrypted sessions the branch or hub router can handle. This is especially valuable at aggregation points where multiple remote sessions terminate.
Government & Regulated Industry Compliance
The ISM-VPN-29's support for Suite B cryptography and ECDSA authentication makes it suitable for deployments that must comply with NSA, FIPS, or other government-mandated encryption standards. Organizations in defense, finance, and healthcare can leverage these capabilities to meet strict data-in-transit encryption requirements.
General
Encryption & Security
Performance
Physical
Environmental
Compliance
Compatibility Notes
Compatible Platforms
The ISM-VPN-29 is designed for the Cisco 2900 Series ISR G2 routers with an available ISM card slot:
- Cisco 2901
- Cisco 2911
- Cisco 2921
- Cisco 2951
IPsec Throughput by Platform (with ISM-VPN-29 installed)
| Router Model | IMIX Throughput | 1400-Byte Throughput |
|---|---|---|
| Cisco 2901 | 145 Mbps | 550 Mbps |
| Cisco 2911 | 150 Mbps | 600 Mbps |
| Cisco 2921 | 220 Mbps | 700 Mbps |
| Cisco 2951 | 385 Mbps | 900 Mbps |
Notes
- The ISM-VPN-29 requires a Cisco IOS release that supports the VPN ISM feature set on the ISR G2 platform.
- The 3900 Series equivalent is the ISM-VPN-39 (sold separately).
- The Cisco ISR 4000 Series does not use an ISM-VPN module; VPN encryption is built into the platform and enabled via the HSEC license.
Downloads & Resources
Frequently Asked Questions
| Part Number | Product | Key Difference |
|---|---|---|
| ISM-VPN-39 | Cisco VPN ISM for 3900 Series | Designed for the Cisco 3900 Series ISR G2 (3925/3945) with higher IPsec throughput up to 1200 Mbps |
| CISCO2911-SEC/K9 | Cisco 2911 Security Bundle | Complete ISR G2 router bundle with security license — pair with ISM-VPN-29 for hardware crypto acceleration |
| FL-4330-HSEC-K9 | Cisco ISR 4330 HSEC License | Next-generation replacement — enables built-in hardware encryption on ISR 4000 Series without a separate module |
| AIM-VPN/SSL-2 | Cisco AIM VPN/SSL Module | Legacy AIM-slot VPN accelerator for older ISR G1 platforms — ISM-VPN-29 is the ISR G2 successor |
