O'Reilly logo
  • Qiang He thinks this is interesting:

The SAs are also protocol specific. There is an SA for each protocol. If two hosts A and B are communicating securely using both AH and ESP, then each host builds a separate SA for each protocol.


Cover of IPSec: The New Security Standard for the Internet, Intranets, and Virtual Private Networks, Second Edition


if use both AH, ESP, 2 SAs for each direction, thus, 4 SAs in total