13-33
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter13 IP Security
IPSec Policies
Note A crypto map can contain a maximum of 6 transform sets .
Available Transform Sets
Configured transform sets available for use in crypto maps. If no transform sets
have been configured on the router, this list contains the default transform sets that
SDM provides.
Note Not all routers support all transform sets (encryption ty pes). Unsupported
transform sets will not appear in the screen.
Not all IOS images support all the transform sets that SDM supports.
Transform sets unsupported by the IOS image will not appear in the screen.
If hardware encryption is turned on, only those transform sets supported by
both hardware encryption and the IOS image will appear in the screen.
Selected Transform Sets
The transform sets that have been selected for this crypto map, in the order in
which they will be used. Both ends of a VPN connection must use the same
transform set, and they can negotiate to determine which set to use. Configuring
multiple transform sets helps ensure that your router can offer a transform set that
the peer will accept. During negotiations, the router will offer transform sets in
the order given in this list. You can use the up and down arrow buttons to reorder
the list.
What Do You Want to Do?
If you want to: Do this:
Add a transform set to the Selected
Transform Sets box.
Select a transform set in the Available Transform Sets box,
and click the right-arrow button.
Remove a transform set from the
Selected Transform Sets box.
Select the transform set you want to remove, and click the
left-arrow button.