To configure a Services Router to transport traffic across a secure IPSec connection, you must define the IPSec tunnel with security associations (SAs), services interfaces, IPSec tunnel endpoints, and IPSec rules to direct traffic to the tunnel.
In a network consisting of Services Routers, you can define manual SAs or dynamic SAs. Manual SAs require you to configure all security parameters of the SA, such as authentication and encryptions algorithms, encryptions keys, and the protocols, in the Services Routers at the tunnel endpoints. Dynamic SAs require you to configure the IKE protocol to manage the negotiation and exchange of encryption keys.
Go on to one of the following topics: