Solved

ESP and AH transform-set command

Posted on 2006-11-15
1
463 Views
Last Modified: 2007-12-19
When I do a crypto ipsec transform-set ?
I see:

ah-md5-hmac
ah-sha-hmac
comp-lzs
esp-des
esp-md5-hmac
esp-null
esp-sha-hmac

I always choose esp-des.
When's the proper time to choose ESP and when's the proper time to choose AH?

0
Comment
Question by:dissolved
1 Comment
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 17949956
You can use AH alone when you are just looking for authentication and anti-replay services without encryption.  If you want encryption you need to use ESP.  ESP also provides authentication.  Typically you are going to use ESP for your VPN tunnel.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now