Manage IPSec Policy
manage_ipsec_policyManage IPSec policies by adding, removing, enabling, or disabling them. Idempotent operations use source and destination addresses with tunnel mode as composite key.
Instructions
Add, remove, enable, or disable an IPSec policy. Idempotent by composite key (srcAddress + dstAddress + tunnel).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| routerId | No | Router ID; omit to use the default router. | |
| action | Yes | Action to perform | |
| srcAddress | Yes | Source CIDR — part of composite idempotency key | |
| dstAddress | Yes | Destination CIDR — part of composite idempotency key | |
| tunnel | No | Tunnel mode — part of composite idempotency key | |
| ipsecAction | No | IPSec action (required for add) | |
| level | No | SA level | require |
| saSourceAddress | No | SA source IP for tunnel mode | |
| saDstAddress | No | SA destination IP for tunnel mode | |
| dryRun | No | Preview changes without applying. |