SecurityDescriptionUsing the tunnel local command, you can configure the local address of a securitytunnel. Using the undo tunnel local command, you can cancel the local address setin the IPSec policy.By default, no IP address at the local end of the security tunnel.This command is applicable to the IPSec module of the operating system and cryptocard.It is not necessary to set a local address for an IPSec policy in isakmp mode, so thiscommand is invalid in this situation. IKE can automatically obtain the local addressfrom the interface where this IPSec policy is applied.As for the IPSec policy in manual mode, it is necessary to set the local addressbefore the SA is created. A security tunnel is set up between the local and peer end,so the local address and remote address must be correctly configured before asecurity tunnel can be set up.For related commands, see ipsec policy (system view),ipsec policy (interfaceview),security acl, tunnel remote, sa duration, sa inbound/outbound, proposal.Example# Configure the local address for the IPSec policy, which is applied at Serial 0 whoseIP address is 10.0.0.1.[3Com]ipsec policy guangzhou 100 manual[3Com-ipsec-policy-guangzhou-100] tunnel local 10.0.0.1[3Com-Serial0]ipsec policy guangzhou4.1.43 tunnel remoteSyntaxtunnel remote ip-addressundo tunnel remoteViewIPSec policy viewParameterip-address: Remote address.87