Hello Infotech, As i mentioned before, there will be only a pair of keys for encryption and decryption. local spi: 9AC6CEDC >>>>>>>>>>>> It will be used for encrypting traffic going into the tunnel. remote spi: DF67E405 >>>>>>>>>>> It will be used for decrypting traffic coming through the tunnel from other end FW So, there is no specific way to track bidirectional flow through the VPN (0.0.0.0/0 proxy ID---- eventually it will pass all traffic through tunnel) . But, if you configure a specific PROXY-ID, for example SRC-1.1.1.1/32 and DST-2.2.2.2/32 and then you may monitor the encap packets/decap packets counter to know whether PAN is receiving or sending as well . ( Bidirectional flow). Thanks
... View more