Packet-based configuration
You control IPSec behavior by defining packet filters in IPSec policies.
An IPSec policy contains a packet filter definition and list of actions
or transforms (pass, discard, use ESP or AH) to apply to the packets.
The packet filter definition contains the following fields:
local address prefix length
(for subnet addresses)
remote address prefix length
(for subnet addresses)
upper-layer protocol (such
as TCP, UDP. or ICMP)
local TCP or UDP port number
remote TCP or UDP port number
You can also select a network service for the filter, such
as telnet, instead of the upper-layer protocol and port numbers.