HI, all, I have a basic question regarding IPsec SA creation, my understanding is always that IPsec SAs are always subset of traffic pairs defined in local crypto ACL, say local crypto ACL protects 10.1.1.0/24 to 10.2.2.0/24, 10.1.1.0/24 to 10.2.3.0...