<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec Unidirectional Tunnel!! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548307#M1125091</link>
    <description>&lt;P&gt;I know that Phase-1 tunnel is bi-directional, but what that means?? And why Phase2 tunnel is said to be unidirectional??&lt;BR /&gt;I get it that in the show commands for ipsec sa it shows inbound sas and outbound sas, so inbound sas for one peer will be seen as outbound sas on other peer and vice-versa. But what it actually means by a unidirectional tunnel for phase2 and phase1 tunnel as bidirectional.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2026 10:40:34 GMT</pubDate>
    <dc:creator>parthrawat979</dc:creator>
    <dc:date>2026-04-27T10:40:34Z</dc:date>
    <item>
      <title>IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548307#M1125091</link>
      <description>&lt;P&gt;I know that Phase-1 tunnel is bi-directional, but what that means?? And why Phase2 tunnel is said to be unidirectional??&lt;BR /&gt;I get it that in the show commands for ipsec sa it shows inbound sas and outbound sas, so inbound sas for one peer will be seen as outbound sas on other peer and vice-versa. But what it actually means by a unidirectional tunnel for phase2 and phase1 tunnel as bidirectional.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 10:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548307#M1125091</guid>
      <dc:creator>parthrawat979</dc:creator>
      <dc:date>2026-04-27T10:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548327#M1125093</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;In IPsec, when people say Phase 1 (IKE) is bi-directional, they mean that a single IKE Security Association (SA) created during Phase 1 is used for communication in both directions between the two peers.&amp;nbsp; &amp;nbsp;&lt;A href="https://www.zelisproviders.com" target="_self"&gt;&lt;FONT size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;zelisproviders com&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp; Once established, that IKE SA allows each side to securely negotiate, manage, and maintain the connection without needing separate “inbound” and “outbound” tunnels—it’s essentially one logical control channel shared by both devices.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 11:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548327#M1125093</guid>
      <dc:creator>julie97cardi</dc:creator>
      <dc:date>2026-04-27T11:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548329#M1125094</link>
      <description>&lt;P&gt;Okay, and what about the phase2 tunnel. I don't get why it couldn't be also bi-directional like phase1?? Is there any specific reason for that or is it like that's how the thing worked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 12:12:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548329#M1125094</guid>
      <dc:creator>parthrawat979</dc:creator>
      <dc:date>2026-04-27T12:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548336#M1125095</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1928717"&gt;@parthrawat979&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phase 1 is considered bi-directional because it establishes a single secure control channel (ISAKMP/IKE SA) that both peers use to negotiate and manage the VPN in both directions, whereas Phase 2 is unidirectional by design ... because it creates separate SAs for each trafic direction ; one SA for outbound traffic and another for inbound. Each with its own keys, sequence numbers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 13:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548336#M1125095</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2026-04-27T13:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548352#M1125098</link>
      <description>&lt;P&gt;So, there's no science behind this? It's just by design that both the phase2 tunnel is unidirectional.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 14:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548352#M1125098</guid>
      <dc:creator>parthrawat979</dc:creator>
      <dc:date>2026-04-27T14:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548363#M1125101</link>
      <description>&lt;P&gt;Yes sir !&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 14:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548363#M1125101</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2026-04-27T14:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Unidirectional Tunnel!!</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548373#M1125102</link>
      <description>&lt;P&gt;I just read somewhere:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IPsec creates two, unidirectional Security Associations, based upon a single Policy Suite (i.e, set of protocols). The only thing that makes one IPsec SA different from the next, are the secret keys used within the specific protocols.&lt;BR /&gt;&lt;/STRONG&gt;This is by design. This way, if someone successfully brute forces one set of keys, they can only decrypt the data in one direction.&amp;nbsp;&lt;BR /&gt;I didn't get the part where the sa's differs from each other.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 15:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-unidirectional-tunnel/m-p/5548373#M1125102</guid>
      <dc:creator>parthrawat979</dc:creator>
      <dc:date>2026-04-27T15:40:21Z</dc:date>
    </item>
  </channel>
</rss>

