A security policy is a rule
that is programmed into the IPsec implementation. It tells the implementation how
to process different datagrams received by the device. For example, security policies
decide if a particular packet needs to be processed by IPsec or not. AH and ESP
entirely bypass those that do not need processing. If security is required, the security
policy provides general guidelines for how it should be provided, and if necessary,
links to more specific detail. Security policies for a device are stored in the
device’s security policy database (SPD).