In a scenario where DHCP over IPSec is deployed, the IPSec negotiation initiator is a DHCP client. The DHCP server's IP address must be specified on the gateway so that some DHCP broadcast packets can be transmitted using an IPSec tunnel.
Enter the system view.
Run ipsec policy policy-name seq-number isakmp
An IPSec policy is created and its view is displayed.
Run ipsec policy-template template-name seq-number
An IPSec policy template is created and its view is displayed.
The DHCP server's IP address is specified.