Holds configuration information for an IPsec SPD
entry.
lifetime
time bytes packets idle
Different lifetime values limited to an IPsec SA.
port-range
start end
This grouping defines a port range, such as that
expressed in RFC 4301, for example, 1500 (Start
Port Number)-1600 (End Port Number).
A port range is used in the Traffic Selector.
This grouping contains the definition of a Traffic
Selector, which is used in the IPsec policies and
IPsec SAs.
tunnel-grouping
local remote df-bit bypass-dscp dscp-mapping
The parameters required to define the IP tunnel
endpoints when IPsec SA requires tunnel mode. The
tunnel is defined by two endpoints: the local IP
address and the remote IP address.