IPsec SPD Rules

Each SPD rule requires two ACL rules, one defining the traffic flows on the tunnel, and one defining the traffic flows within the tunnel. The protocol to which the SPD rule applies must be identical for both ACL rules, and the sequence number used with the ACL rules, must be consecutive.

SPD Rules and Related Actions

SPD Rule Action Address Protocol Sequence Number
BYPASS Permit Public address Applicable protocol N
Deny Tunnel internal address Applicable protocol N + 1
PROTECT Deny Public address Applicable protocol N
Permit Tunnel internal address Applicable protocol N + 1
DISCARD Deny Public address Applicable protocol N
Deny Tunnel internal address Applicable protocol N + 1