IPsec SPD Rules
Each SPD rule requires two ACL rules, one defining the traffic flows on the tunnel, and one defining the traffic flows within the tunnel. The protocol to which the SPD rule applies must be identical for both ACL rules, and the sequence number used with the ACL rules, must be consecutive.
SPD Rules and Related Actions
| SPD Rule | Action | Address | Protocol | Sequence Number |
|---|---|---|---|---|
| BYPASS | Permit | Public address | Applicable protocol | N |
| Deny | Tunnel internal address | Applicable protocol | N + 1 | |
| PROTECT | Deny | Public address | Applicable protocol | N |
| Permit | Tunnel internal address | Applicable protocol | N + 1 | |
| DISCARD | Deny | Public address | Applicable protocol | N |
| Deny | Tunnel internal address | Applicable protocol | N + 1 |