Hold down for a sec!
I don't really understand the purpose of the thread here. u ask for IPsec policy but u r talking about firewalling features.
r u 1 of these guys that think IPsec is a firewall?

IPsec is designed for peer-to-peer or site-to-site flows with encryption, VPN tunneling, anti replay, certificates & so on...
I wrote a thread on topic hereby: http://www.antionline.com/showthread...hreadid=243795