Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

transform set name

Hi all

I am configuring a site to site vpn and cisco client vpn for my ASA

can i check do i need to created two transform set name, one for site to site and one for client vpn? or i should just created one transform set name?

i went through certain sample configuration file for site to site and client vpn and i realised most of them only make use of a single transform set name

thank!

2 REPLIES
Silver

Re: transform set name

One should do. You can invoke the trasnform set for both LAN2LAN and dynamic users

Hall of Fame Super Silver

Re: transform set name

As long as the LAN to LAN and dynamic users will use the same combination of security protocols and algorithms then only a single transform set needs to be configured. If there is to be any difference in security protocols or algorithms (for example if the LAN to LAN will use SHA and the dynamic users will use MD5) then you would need separate transform sets.

HTH

Rick

329
Views
3
Helpful
2
Replies