Add Traffic Selector ACL

This ACL is used in the IKEv2 security association negotiation as well as when Secure Firewall makes decisions about when to encrypt traffic. It does not encrypt traffic denied in the ACL when the deny statement comes before the permit statement.

  1. Navigate to Objects > Object Management > Access List > Extended > Add Extended Access List.
  2. Enter a name for the ACL and then click Add to add the Access Control Entries (ACE).
    • a. The first entry denies traffic to the network object type group containing the Secure Access resolvers. Optionally, traffic to the 146.112.0.0/16 and 155.190.0.0/16 subnets can also be denied.

    • b. The second entry allows traffic from any IPv4 address to any IPv4 address. This is also the entry IKEv2 uses to negotiate the IPSec Security Association (traffic selector).

  3. After you have added the entries, click Save.