tscf-protocol-policy

Configures the protocol policy to enable Policy-based forwarding.

Parameters

name
Name of this protocol policy configuration element.
ip-address
Criteria to match inner tunnel packet's destination IP against. For non-tunneled packets, this parameter is matched against the source IP Address. This parameter is optional. This parameter supports an IPv4 or IPv6 address.
port
Criteria to match inner tunnel packet's destination port against. For non-tunneled packets, this parameter is matched against the source port. This parameter is optional.
transport-type
Criteria to match inner tunnel packet's transport protocol.
  • Default: empty
  • Values: UDP | TCP | TLS | SCTP
realm-id
The egress realm where this protocol policy forwards matching packets. Those packets are forwarded to the gateway that services the interface associated with the named realm.
remote-ip-address
An optional post-NAT destination IP address target of detunneled packets matching this protocol policy. When matching traffic is forwarded from the non-tunneled side to tunneled side, the source IP address must match the remote-ip-address. The source IP address will be changed back to the original destination IP address within the tunneled packet.

Path

tscf-protocol-policy is an element within the security, and then tscf path. The full path from the topmost ACLI prompt is security, and then tscf, and then tscf-protocol-policy