
Configuring IPsec Services
1-10
304111-B Rev 00
Policy Criteria Specification
IPsec software inspects IP packet headers based on the specified criteria to
determine whether a policy applies to a data packet.
You must include at least one of the following criteria, and you may specify all
three criteria in an IPsec policy:
• IP source address
• IP destination address
• Protocol
To specify the protocol criterion, you must provide the numeric value assigned to
the protocol for use over the Internet. You can specify only a single protocol value
for each policy. The protocol number is represented in the 1-byte protocol field in
an IP packet header.
Refer to Appendix D
for a list of protocol numbers. To obtain the most recent list
of the numeric values assigned to various protocols, see the Internet Assigned
Numbers Authority (IANA) Web site at:
http://www.iana.org
The direct path to the list of legal values that you can specify for an IPsec policy
protocol criterion as of this printing is:
http://www.isi.edu/in-notes/iana/assignments/protocol-numbers
Comentarios a estos manuales