For each IPSec tunnel, there are two Security Associations (SAs) formed: inbound and outbound. Although we tend to refer to this VPN Tunnel in the singular, it actually consists of two "flows" of encrypted data: inbound and outbound. A similar concept is employed in the state table element "connections" where each connection is tracked as two separate flows referred to as c2s (client to server - outbound) and s2c (server to client - inbound).
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm