Cisco Cisco ASR 5700
![Cisco](https://files.manualsbrain.com/attachments/7380d0050044647c30f5c24bbbf5d0c0b6d9bb84/common/fit/150/50/faa183d287233c52228cfea3dbc2a127fe780f60564fcb0955d9c3d1cd23/brand_logo.png)
Crypto IPSec Transform Set Configuration Mode Commands
▀ mode
▄ Command Line Interface Reference, StarOS Release 17
2870
mode
Configures the IPSec encapsulation mode for an existing or new transform set. For a new transform set, you must
specify transform set parameters as described for the crypto ipsec transform-set command in the Context
Configuration Mode Commands chapter.
specify transform set parameters as described for the crypto ipsec transform-set command in the Context
Configuration Mode Commands chapter.
Product
PDSN
HA
GGSN
PDIF
Privilege
Security Administrator
Syntax
mode { transport | tunnel }
transport
Specifies that the transform set only protects the upper layer protocol data portions of an IP datagram, leaving
the IP header information unprotected. Default: Disabled
the IP header information unprotected. Default: Disabled
Important:
This mode should only be used if the communications end-point is also the cryptographic end-point.
tunnel
Specifies that the transform set protects the entire IP datagram.
This mode should be used if the communications end-point is different from the cryptographic end-point as in
a VPN. Default: Enabled
This mode should be used if the communications end-point is different from the cryptographic end-point as in
a VPN. Default: Enabled
Usage
This command specifies the encapsulation mode for the transform set.
Example
The following command configures the transforms set’s encapsulation mode to transport:
mode transport