TMS zl Management and Configuration Guide ST.1.2.100916

A-142
Command-Line Reference
IPsec Policy Context
Table A-41. IPsec Policy Traffic Selector Command Options
For example:
hostswitch(tms-module-<slot ID>:ipsec:<action>)#
traffic-selector protocol tcp local any port any remote
host 10.2.3.3 port 89
This command is also available from the IPsec policy, IPsec policy bypass, and
IPsec policy deny contexts.
IPsec Auto Keys Context
This context includes the commands specific for configuring an IPsec policy
that uses IKE. (It is available only when the TMS zl Module is in routing mode.)
Parameter Options
protocol any
<1-255>
ah
esp
•ip
•igmp
•gre
•l2tp
•ospf
•pim
tcp [port <any | port number>] *
udp [port <any | port number>] *
icmp < any | echo** | timestamp** >
address any
host <IP address>
network address/prefix length
ip-range <start IP address> <end IP address>
address <address object>
*If you use TCP or UDP for the traffic selector, you must enter port and specify a
port after both the local address and the remote address.
**If you select echo or timestamp, the tunnel must use manual keying instead of
IKE in your IPsec policy.