
3-16
CiscouBR924 Software Configuration Guide
OL-0337-05 (8/2002)
Chapter3 Advanced Data-Only Configurations
IPSec (3DES) Example
IPSec (3DES) ExampleThe IPSec 3DES encryption feature set is identical to the IPSec encryption feature set except that it 
supports the 168-bit Triple DES (3DES) standard in addition to the standard 56-bit IPSec encryption. 
The 168-bit encryption feature set requires a CiscoIOS image that supports it and provides a level of 
security suitable for highly sensitive and confidential information such as financial transactions and 
medical records.
Note Cisco IOS images with strong encryption (including, but not limited to, 168-bit [3DES] data en cryption 
feature sets) are subject to United States government export controls and have limited distribution. 
Strong encryption images to be installed outside the Unite d States may require an export license. 
Customer orders may be denied or subject to delay due to United States governme nt regulations. When 
applicable, the purchaser or user must obtain local import and use authorizations for all encryption 
strengths. Contact your sales representative or distributor for more informa tion, or send an e-mail to 
export@cisco.com. 
Configuration for 3DES encryption is identical to that for standard IPSec, except that the transformation 
set should specify esp-3des instead of esp-des. For example, the following configuration is identical to 
the configuration shown in “IPSec (56-bit) Example” section on page3-11, except for the line in bold:
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname Router
!
clock timezone - 0 6
ip subnet-zero
no ip domain-lookup
!
crypto isakmp policy 1 
 hash md5 
 authentication pre-share 
 lifetime 5000 
crypto isakmp key 1234567890 address 30.1.1.1 
crypto isakmp identity hostname 
! 
crypto ipsec transform-set test-transform ah-md5-hmac esp-3des esp-md5-hmac 
! 
 crypto map test-ipsec local-address cable-modem0 
 crypto map test-ipsec 10 ipsec-isakmp 
 set peer 30.1.1.1 
 set transform-set test-transform 
 match address 200 
!
interface Ethernet0
 ip address 192.168.100.1 255.255.255.0
 no ip directed-broadcast
!
interface cable-modem0
 ip address dhcp
 no ip directed-broadcast
 no keepalive
 no cable-modem compliant bridge
 crypto map test-ipsec 
router rip