key words Dir in, out, fwd difference security policy syntax meaning output policy dir out SP works as a selector on outgoing packets to select which are to be encrypted+encapsulated and which not input policy dir in SP works as a selector on incoming packets which already have been decrypted+decapsulated and have a destination IP local on the system forward policy dir fwd SP works as a selector on incoming packets which already have been decrypted+decapsulated and have a destination IP which is not local, thereby packets which are to be forwarded (routed) So: