"finely", i. e. you can, e. g., specify the source IP address or the source port. If there is a
Additional IPv4 Traffic Filter configured, it is used to negotiate the IPSec phase 2 SAs;
the route only determines which data traffic is to be routed.
If an IP packet does not match the defined Additional IPv4 Traffic Filter it is discarded.
If an IP packet meets the requirements in an Additional IPv4 Traffic Filter , IPSec phase 2
negotiation begins and data traffic is transferred over the tunnel.
Note
The parameter Additional IPv4 Traffic Filter is only relevant to the initiator of the
IPSec connection, it only applies to outgoing data traffic.
Note
Please note that the phase 2 policies must be configured identically on both of the
IPSec tunnel endpoints.
Add new entries with Add.
Fields in the menu Basic Parameters
Field
Description
Description
Enter a description for the filter.
Protocol
Select a protocol. The
,0
option (default value) matches all
protocols.
Source IP Address/
Netmask
Enter, if required, the source IP address and netmask of the
data packets.
Possible values:
•
,0
•
>
: Enter the IP address of the host.
•
92B
(default value): Enter the network address and the
related netmask.
Source Port
Only for Protocol =
)%
or
/-
Enter the source port of the data packets. The default setting
bintec elmeg GmbH
14 VPN
be.IP 4isdn
243