![Cisco SA-VAM - VPN Acceleration Module Скачать руководство пользователя страница 46](http://html.mh-extra.com/html/cisco/sa-vam-vpn-acceleration-module/sa-vam-vpn-acceleration-module_installation-and-configuration-manual_66316046.webp)
4-6
VPN Acceleration Module 2+ (VAM2+) Installation and Configuration Guide
OL-5979-03
Chapter 4 Configuring the SA-VAM2+
Configuration Tasks
Examples of acceptable transform combinations are as follows:
•
ah-md5-hmac
•
esp-des
•
esp-3des
and
esp-md5-hmac
•
ah-sha-hmac
and
esp-des
and
esp-sha-hmac
•
comp-lzs
The parser will prevent you from entering invalid combinations; for example, once you specify an AH
transform it will not allow you to specify another AH transform for the current transform set.
IPSec Protocols: AH and ESP
Both the AH and ESP protocols implement security services for IPSec.
AH provides data authentication and antireplay services.
ESP provides packet encryption and optional data authentication and antireplay services.
ESP Encryption Transform
(Note: If an
ESP
Authentication Transform
is used, you must
pick one.)
esp-aes
esp-aes 128
esp-aes 192
esp-aes 256
esp-des
esp-3des
esp-null
ESP with the 128-bit Advanced Encryption
Standard (AES) encryption algorithm
ESP with the 128-bit AES encryption algorithm
ESP with the 192-bit AES encryption algorithm
ESP with the 256-bit AES encryption algorithm
ESP with the 56-bit Data Encryption Standard
(DES) encryption algorithm
ESP with the 168-bit DES encryption algorithm
(3DES or Triple DES)
Null encryption algorithm
ESP Authentication Transform
(Pick up to one.)
esp-md5-hmac
esp-sha-hmac
ESP with the MD5 (HMAC variant)
authentication algorithm
ESP with the SHA (HMAC variant)
authentication algorithm
IP Compression Transform (Pick up to one.)
comp-lzs
IP compression with the Lempel-Ziv-Stac
(LZS) algorithm
Table 4-1
Allowed Transform Combinations (continued)
Transform type
Transform
Description