Oracle SBC IPsec encryption domain
We have the following network topology:
- Oracle SBC Local Phase 1/IKE interface IP 10.205.101.150, Remote Phase 1/IKE interface IP 46.x.x.x/32
- 2. Oracle SBC Local Phase 2 IPsec IP 10.205.101.150, Remote Phase 2/IPsec IPs 217.x.x.x /27
Local peer is located behind 1:1 NAT.
How should be the remote encryption domain 217.x.x.x /27 being configured in the ipsec→security-policy - with remote-ip-mask 255.255.255.224 or 255.255.255.255;
and remote-ip-mask in the outbound-sa-fine-grained-mask should be 255.255.255.255 or 255.255.255.224?
1. What is exact difference between remote-ip-mask in ipsec>security policy config and remote-ip-mask in the outbound-sa-fine-grained-mask ?
2. Do I need to add a manual config in the ipsec security-association?
Product - Oracle SBC,