IKEv1 specifying an ike line with aes-sha2_384 and an esp line of esp=aes On some versions this caused the inbound and outbound IPsec SA keys (not IKE keys) to be identical (eg XXXbound key was using YYYbound key)