Chapter13 IP Security
IPSec Policies
13-32
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
independently. It thus ensures that if one key is compromised, no other keys will
be. If you enable PFS, you can specify use of the Diffie-Hellman group1, group2,
or group5 method.
Note If your router does not support group5, it will not appear in the list.

Enable Reverse Route Injection

Reverse Route Injection (RRI) is used to populate the routing table of an internal
router running Open Shortest Path First (OSPF) protocol or Routing Information
Protocol (RIP) for remote VPN clients or LAN-to-LAN sessions.
Reverse Route Injection dynamically adds static routes to the clients connected to
the Easy VPN server.
Add or Edit Crypto Map: Peer Information Panel
Use this panel to add or edit crypto map peer information. The list of peers
associated with this crypto map is shown in the Current List box. You can add new
peers, remove peers, or edit them. You can specify a peer using either an IP
address or a host name. Multiple peers provide the router with more routing paths.
Add or Edit Crypto Map: Transform Sets Panel
Use this window to add, edit, and order the transform sets used in the crypto map.
The devices at both ends of the VPN connection must use the same transform set,
and the can negotiate to determine which transform set to use. Configuring
multiple transform sets helps ensure that the router can offer a transform set that
the negotiating peer can agree to use.
If you want to: Do this:
Add a peer to the Current List. Click Add, and enter the IP address or host name of the peer.
Remove a peer from the Current List. Select the peer, and click Remove.