i have a question. When we have a L2L VPN and we have enabled tunnel per gateway pair, it will create only one SA or only one pair of SAs? From what i know, SAs are undirectional, so the minimum we need is 2 for phase 2, am i right?
Second question, does every SA include the 'return' traffic as well (thus the whole session) or the reason we need 2nd Ipsec SA is for the return traffic? Because if it is the former, if i only need one way communication , then in theory one Ipsec SA should be enough?