cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
698
Views
0
Helpful
3
Replies

IPSEC Transform Set

DEV1389
Level 1
Level 1

Hello All,

 

I want to know the difference between ESP-SHA512-HMAC and ESP-AES 256 for IPSec transform set . Which of them provides us encryption and integrity protection at the sametime.

 

Secondly for ISE Configuration which probes can be used from (CTS , HTTP , RADius , DHCP ) . As per my knowledge, we can use DHCP/Radius only. Any comments?

 

 

Regards

3 Replies 3

ESP-SHA512-HMAC is the integrity transform and ESP-AES 256 is the encryption transform. If you want to have it integrated, you can use a transform with "GCM" in the name. That is an authenticated encryption with authenticated data (AEAD). I assume that is what you are looking for with "at the sametime"

 

For the ISE, RADIUS and DHCP are the typical probes. DHCP is ideally used with the help of the device-sensor on the switch.

Hello , 

 

As per my info ESP-AES 256 we can use for both encryption and intergrity . Right ?.

 

With Cisco documentation we can also HTTP as probe . but do we have any preference among these probes or no ?.

 

Best Wishes

WAQ

ESP-AES alone only provides the encryption and you always need an additional integrity transform.

 

For sure you can use the HTTP probe. But it all depends on what you want to achieve. For HTTP you should always think about how to get your probe-data to the PSN. You surely don't want to use SPAN. Of course you could use some redirection and/or the CPP. But perhaps there are other/better ways to achieve your goal.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card