TMS zl Management and Configuration Guide ST.1.2.100916

A-155
Command-Line Reference
IPsec Policy Context
For example:
hostswitch(tms-module-<slot ID>:ipsec:bypass)# traffic-
selector protocol tcp local 192.168.2.0/26 port any remote
host 192.168.2.1 port 443
preview
Before you apply the IPsec policy, you should preview it to make sure
everything is correct. To preview your policy, enter the following command:
Syntax: preview
For example:
hostswitch(tms-module-<slot ID>:ipsec:bypass)# preview
IPsec policy
-------------------------------------------------------
*Policy Name: testpol
Status: Enabled
Action: Bypass
Direction: Both
Position: 1
Traffic Selector
*Protocol: TCP
*Local Address: 192.168.2.0/26
*Local Port: Any
*Remote Address: 2.2.2.0/24
*Remote Port: 443
IPsec Policy Deny Context
The IPsec policy deny context includes the commands specific to configuring
a deny IPsec policy. This type of policy selects traffic that is not secured by
an IPsec SA and is dropped instead. (This context is available only when the
TMS zl Module is in routing mode.)