cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
487
Views
3
Helpful
2
Replies

transform set name

d_unafraid
Level 1
Level 1

Hi all

I am configuring a site to site vpn and cisco client vpn for my ASA

can i check do i need to created two transform set name, one for site to site and one for client vpn? or i should just created one transform set name?

i went through certain sample configuration file for site to site and client vpn and i realised most of them only make use of a single transform set name

thank!

2 Replies 2

attrgautam
Level 5
Level 5

One should do. You can invoke the trasnform set for both LAN2LAN and dynamic users

As long as the LAN to LAN and dynamic users will use the same combination of security protocols and algorithms then only a single transform set needs to be configured. If there is to be any difference in security protocols or algorithms (for example if the LAN to LAN will use SHA and the dynamic users will use MD5) then you would need separate transform sets.

HTH

Rick

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: