TMS zl Management and Configuration Guide ST.1.1.100430
A-155
Command-Line Reference
IPsec Policy Context
traffic-selector
With this command, you configure the VPN traffic selector, which determines
the traffic to which this policy is applied. For a policy with the bypass action,
this traffic is forwarded normally without being secured by an SA.
To set the traffic selector, enter the following command:
Syntax: traffic-selector protocol <protocol> local <address> remote address
<address> [port <port>]
The available options for the command are shown in Table A-39.
Table A-42. IPsec Policy Traffic Selector Command Options
Parameter Options
protocol •any
• <1-255>
•ah
•esp
•ip
•igmp
•gre
•l2tp
•ospf
•pim
• tcp [port <any | port number>] *
• udp [port <any | port number>] *
• icmp < any | echo** | timestamp** >
address •any
•host <IP address>
• network address/prefix length
• ip-range <start IP address> <end IP address>
• address <address object>
*If you use TCP or UDP for the traffic selector, you must enter port and specify a port
after both the local address and the remote address.
**If you select echo or timestamp, the tunnel must use manual keying instead of IKE
in your IPsec policy.