Chapter8 Site-to-Site VPN
Create Site to Site VPN
8-44
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
ESP Encryption
The type of Encapsulating Security Protocol (ESP) encryption used. If ESP
encryption is not configured for this transform set, this column will be empty.
ESP Authentication
The type of ESP authentication used. If ESP authentication is not configured for
this transform set, this column will be empty.
AH Authentication
The type of Authentication Header (AH) authentication used. If AH
authentication is not configured for this transform set, this column will be empty.
IP Compression
If IP compression is configured for this transform set, this field contains the value
COMP-LZS.
Note IP compression is not supported on all routers.
Mode
This column contains one of the following:
TransportEncrypt data only. Transport mode is used when both endpoints
support IPsec. Transport mode places the authentication header or
encapsulated security payload after the original IP header; thus, only the IP
payload is encrypted. This method allows users to apply network services
such as quality-of-service (QoS) controls to encrypted packets.
TunnelEncrypt data and IP header. Tunnel mode provides stronger
protection than transport mode. Because the entire IP packet is encapsulated
within AH or ESP, a new IP header is attached, and the entire datagram can
be encrypted. Tunnel mode allows network devices such as routers to act as
an IPsec proxy for multiple VPN users.
Type
Either User Defined, or SDM Default.