Chapter17 IP Security
Transform Set
17-18
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Add or Edit Transform Set
Use this window to add or edit a transform set.
To obtain a description of the allowable transform combinations, and descriptions
of the transforms, click Allowable Transform Combinations.
Note Not all routers support all transform sets (encryption types). Unsupported
transform sets will not appear in the screen.
Not all IOS images support all the transform sets that Cisco SDM supports.
Transform sets unsupported by the IOS image will not appear in the screen.
If hardware encryption is turned on, only those transform sets supported by
both hardware encryption and the IOS image will appear in the screen.
Easy VPN servers only support tunnel mode. Transport mode is not supported
by Easy VPN servers.
Easy VPN Servers only support transform sets with ESP encryption. Easy
VPN servers do not support the AH algorithm.
Easy VPN Servers do not support ESP-SEAL encryption.

Name of this transform set

This can be any name that you want. The name does not have to match the name
in the transform set that the peer uses, but it may be helpful to give corresponding
transform sets the same name.

Data integrity and encryption (ESP)

Check this box if you want to provide Encapsulating Security Payload (ESP) data
integrity and encryption.
Integrity Algorithm
Select one of the following:
ESP_MD5_HMAC. Message Digest 5.
ESP_SHA_HMAC. Security Hash Algorithm.