cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
895
Views
0
Helpful
4
Replies

Regarding selection of a transform set during security association

shikharverma201
Level 1
Level 1

How to choose a transform set used by a device during the security associations process? On what parameter, a device chooses a transform set from a list of transform sets??

1 Accepted Solution

Accepted Solutions

All algorithms must match (encryption and hashing/integrity) in order to establish a tunnel.

The device initiating the tunnel will send it's supported algorithms to the peer, which will then attempt to find a match, starting with the highest priority first until a match is found and the tunnel is built.

View solution in original post

4 Replies 4

Hi,

If you specify a transform set with multiple algorithms, the router/firewall will attempt to negotiate will the peer router/firewall in order of priority (highest priority first) until they mutual agree upon a algorithm both peers support.

 

HTH

Hi! Thanks for such quick answers. However, I have still doubt about "what parameter or condition decides the mutual agreement and who decide on which priority level peers should agree? Is it automatic or administrators define fixed transform sets for both peers?

 

All algorithms must match (encryption and hashing/integrity) in order to establish a tunnel.

The device initiating the tunnel will send it's supported algorithms to the peer, which will then attempt to find a match, starting with the highest priority first until a match is found and the tunnel is built.

shikharverma201
Level 1
Level 1

@Rob Ingram Thank you very much for the clarification. It got my doubts clear. Thanks again.