For each IPSec tunnel, there are two Security Associations (SAs) formed: inbound and outbound. Although we tend to refer to this VPN Tunnel in the singular, it actually consists of two "flows" of encrypted data: inbound and outbound. A similar concept is employed in the state table element "connections" where each connection is tracked as two separate flows referred to as c2s (client to server - outbound) and s2c (server to client - inbound).
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com