656client transform-setsUse client transform-sets to specify IPsec transform sets supported by a GM.Use undo client transform-sets to restore the default.Syntaxclient transform-sets transform-set-name&<1-6>undo client transform-setsDefaultA GM supports the IPsec transform set configured with the following security parameters:• The ESP security protocol.• The tunnel or transport encapsulation mode.• The DES-CBC, 3DES-CBC, AES-CBC-128, AES-CBC-192, or AES-CBC-256 encryptionalgorithm.• The MD5 or SHA1 authentication algorithm.ViewsGDOI GM group viewPredefined user rolesnetwork-adminParameterstransform-set-name&<1-6>: Specifies a space-separated list of up to six IPsec transform sets bytheir names. An IPsec transform set name is a case-insensitive string of 1 to 63 characters.Usage guidelinesThis command specifies the IPsec transform sets supported in registration and rekey processes.• During GM registration, a GM terminates the negotiation with the KS if the IPsec transform setsent by the KS is not supported, and the registration fails.• During rekey, the GM discards rekey messages received from the KS if the IPsec transform setsent by the KS is not supported.GMs support only the ESP security protocol. For a successful registration, do not specify an IPsectransform set that uses the AH security protocol for GMs.Examples# Specify the supported IPsec transform set as gdoi-esp-aes for the GDOI GM group abc. system-view[Sysname] gdoi gm group abc[Sysname-gdoi-gm-group-abc] client transform-sets gdoi-esp-aesRelated commandsgdoi gm groupdisplay gdoi gmUse display gdoi gm to display GDOI GM group information, including GDOI configurationparameters, negotiation parameters, and the IPsec information obtained after successfulregistrations.