IPSEC Tunnel
I’m looking at the IP SEC configuration in tunnel mode (AH/ESP) and I do not have a clear picture regarding inner and outer ip addresses configured in the Security Association and where they are configured on the SBC.
I mean, in tunnel mode, local-ip-addr is the IP address configured in the network-interface element and specify the inner IP address contained in the original packet.
The question is: where does the local-ip-addr in the tunnel-mode sub element is configured in the SBC?
Looking at the example I found local-ip-addr and remote-ip-addr in main SA menu and under the tunnel mode sub element always match and it does not help me in the understanding.