You can set up policy-based IPSec VPN tunnels between local subnets and peer subnets.

Note: If you connect to a remote site by using an IPSec VPN tunnel, dynamic routing on the edge uplink cannot learn the IP address of that site.

The task topics in this section explain the steps to configure a policy-based IPSec VPN site.