17-7
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Chapter17 IP Security
IPSec Policies
Add or Edit Crypto Map: Transform Sets
Use this window to add and edit the transform set used in the crypto map. A cryp to
map includes the hostnames or IP addresses of the peers involved in the security
association. Multiple peers provide the router with multiple routes for encrypted
data. However, the devices at both ends of the VPN connection must use the same
transform set.
Use the Crypto Map Wizard if it is sufficient for your router to offer a crypto map
with one transform set.
Use Add New Crypto Map... with Use Add Wizard unchecked if you want to
manually configure a crypto map with multiple transforms sets (up to six) to
ensure that the router can offer one transform set that the peer it is negotiating
with will accept. If you are already in the Crypto Map Wizard, exit the wizard,
uncheck Use Add Wizard, and click Add New Crypto Map....
If you manually configure a crypto map with multiple transforms sets, you can
also order the transform sets. This will be the order that the router will use to
negotiate which transform set to use.

Available Transform Sets

Configured transform sets available for use in crypto maps. In the Crypto Map
Wizard, the available transform sets are in the Select Transform Set drop-down
list.
If no transform sets have been configured on the router, only the default transform
sets provided with Cisco SDM are shown.
Note Not all routers support all transform sets (encryption types). Unsupported
transform sets will not appear in the window.
Not all IOS images support all the transform sets that Cisco SDM supports.
Transform sets unsupported by the IOS image will not appear in the window.
If hardware encryption is turned on, only those transform sets supported by
both hardware encryption and the IOS image will appear in the window.