Configures the IPSec
encapsulation mode.
Platform:
ASR 5000
ASR
5500
Product:
PDSN, HA, GGSN, PDIF
Privilege:
Security Administrator,
Administrator
Syntax
mode { transport | tunnel }
mode transport
Specifies that the
transform set only protects the upper layer protocol data portions
of an IP datagram, leaving the IP header information unprotected.
Default: Disabled
IMPORTANT:
This mode should only
be used if the communications end-point is also the cryptographic end-point.
mode tunnel
Specifies that the
transform set protects the entire IP datagram.
This mode should be
used if the communications end-point is different from the cryptographic
end-point as in a VPN. Default: Enabled
Usage:
This command specifies
the encapsulation mode for the transform set.
Example:
The following command
configures the transforms set’s encapsulation mode to transport:
mode transport