
Configuring IPsec Services
1-10
308630-14.00 Rev 00
If the packet does not match any policy or matches a drop policy, the router rejects
the packet. When a packet does not match any policy, IPsec’s default action is to
drop it.
For an inbound security policy, the action may be:
•Drop
• Bypass
•Log
Drop and bypass are mutually exclusive. The log action may be added to either, or
used alone.
Outbound Policies
An outbound policy determines how a security gateway processes data packets for
transmission across an untrusted network. You must assign an outbound policy for
all unicast traffic leaving an IPsec interface.
For an outbound policy, the action specification may be:
• Protect
•Drop
• Bypass
•Log
Any outbound policy with a protect action specification is mapped to a Protect
SA. See “
Summarizing Security Policies and SAs” on page 1-14 for detailed
information about Protect and Unprotect SAs.
Drop, protect, and bypass are mutually exclusive. The log action may be added to
any of the three, or used alone.
Policy Criteria Specification
IPsec software inspects IP packet headers based on the specified criteria to
determine whether a policy applies to a data packet.
You must include at least one of the following criteria, and you may specify all
three criteria in an IPsec policy:
• IP source address
Comentários a estes Manuais