Configuring Transform Sets for IKEv1
Note |
Only tunnel mode is supported. |
enable
configure terminal
crypto ipsec
transform-set aesset esp-aes 256 esp-sha-hmac
mode tunnel
end
- Optional Configurations
Use the clear crypto sa command to clear existing IPsec associations in a transform set.
There are complex rules defining the entries that you can use for transform arguments. These rules are explained in the crypto ipsec transform-set command. For more information, see About Transform Sets.Router # clear crypto sa ? counters Reset the SA counters map Clear all SAs for a given crypto map peer Clear all SAs for a given crypto peer spi Clear SA by SPI vrf VRF (Routing/Forwarding) instance