<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN SA question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51549#M10205</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a question. When we have a L2L VPN and we have enabled tunnel per gateway pair, it will create only one SA or only one pair of SAs? From what i know, SAs are undirectional, so the minimum we need is 2 for phase 2, am i right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second question, does every SA include the 'return' traffic as well (thus the whole session) or the reason we need 2nd Ipsec SA is for the return traffic? Because if it is the former, if i only need one way communication , then in theory one Ipsec SA should be enough?&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2019 06:41:38 GMT</pubDate>
    <dc:creator>Alex_Krikorian</dc:creator>
    <dc:date>2019-04-23T06:41:38Z</dc:date>
    <item>
      <title>VPN SA question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51549#M10205</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a question. When we have a L2L VPN and we have enabled tunnel per gateway pair, it will create only one SA or only one pair of SAs? From what i know, SAs are undirectional, so the minimum we need is 2 for phase 2, am i right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second question, does every SA include the 'return' traffic as well (thus the whole session) or the reason we need 2nd Ipsec SA is for the return traffic? Because if it is the former, if i only need one way communication , then in theory one Ipsec SA should be enough?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 06:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51549#M10205</guid>
      <dc:creator>Alex_Krikorian</dc:creator>
      <dc:date>2019-04-23T06:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SA question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51600#M10217</link>
      <description>I believe you need the second SA for the return traffic, thus they are always created in pairs.</description>
      <pubDate>Tue, 23 Apr 2019 17:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51600#M10217</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-23T17:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SA question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51603#M10218</link>
      <description>The SA created from site-A to B will support the session, so the forward and return traffic. It will not support a session started from site-B to A though, so there will be a new SA created for that traffic.</description>
      <pubDate>Tue, 23 Apr 2019 18:10:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51603#M10218</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-04-23T18:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SA question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51628#M10225</link>
      <description>&lt;P&gt;I thought so, i just wanted to confirm by having my hands on a per gateway pair vpn to check it , but i didnt. So unless we want traffic initiated from both ends, one SA should be enough. Thanks for verifying!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 06:49:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-SA-question/m-p/51628#M10225</guid>
      <dc:creator>Alex1041</dc:creator>
      <dc:date>2019-04-24T06:49:13Z</dc:date>
    </item>
  </channel>
</rss>

