Why there are so many sas are being created?

Hi Team,

Any idea with version 1.4.2 why so many SAs are being created?

vyos@R1:~$ show vpn ipsec sa
Connection             State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID     Proposal
---------------------  -------  --------  --------------  ----------------  ----------------  ------------  ---------------------------------------
peer_10-10-30-100_vti  down     1s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     1s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     1s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     2s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     2s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     2s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     2s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     2s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     2s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     3s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     3s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     3s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     3s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     3s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     3s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     4s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     4s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     4s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     4s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     4s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     5s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     5s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     5s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     5s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     5s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     6s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     6s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  down     6s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  up       1s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  up       1s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
peer_10-10-30-100_vti  up       1s        0B/0B           0B/0B             10.10.30.100      10.10.30.100  AES_CBC_256/HMAC_SHA2_256_128/MODP_1536
vyos@R1:~$

could you please share your configuration,
do that with `show configuration commands | strip-private

Here is the configuration

vyos@R1:~$ show configuration commands | strip-private
set interfaces ethernet eth0 address 'xxx.xxx.10.100/24'
set interfaces ethernet eth0 hw-id 'xx:xx:xx:xx:xx:9e'
set interfaces ethernet eth1 address 'xxx.xxx.20.100/24'
set interfaces ethernet eth1 hw-id 'xx:xx:xx:xx:xx:a8'
set interfaces ethernet eth2 address 'xxx.xxx.20.100/24'
set interfaces ethernet eth2 hw-id 'xx:xx:xx:xx:xx:b2'
set interfaces loopback lo
set interfaces vti vti1 address 'xxx.xxx.1.1/30'
set interfaces vti vti2 address 'xxx.xxx.2.1/30'
set load-balancing wan interface-health eth0 failure-count '3'
set load-balancing wan interface-health eth0 nexthop 'xxx.xxx.10.200'
set load-balancing wan interface-health eth0 success-count '2'
set load-balancing wan interface-health eth1 failure-count '3'
set load-balancing wan interface-health eth1 nexthop 'xxx.xxx.20.200'
set load-balancing wan interface-health eth1 success-count '2'
set load-balancing wan rule 10 inbound-interface 'eth2'
set load-balancing wan rule 10 interface eth0 weight '1'
set load-balancing wan rule 10 interface eth1 weight '1'
set load-balancing wan rule 10 protocol 'all'
set protocols static route xxx.xxx.0.0/0 next-hop xxx.xxx.10.200 interface 'eth0'
set protocols static route xxx.xxx.0.0/0 next-hop xxx.xxx.20.200 distance '5'
set protocols static route xxx.xxx.0.0/0 next-hop xxx.xxx.20.200 interface 'eth1'
set protocols static route xxx.xxx.40.100/32
set service ssh
set system config-management commit-revisions '100'
set system conntrack modules ftp
set system conntrack modules h323
set system conntrack modules nfs
set system conntrack modules pptp
set system conntrack modules sip
set system conntrack modules sqlnet
set system conntrack modules tftp
set system console device ttyS0 speed '115200'
set system host-name xxxxxx
set system login user xxxxxx authentication encrypted-password xxxxxx
set system login user xxxxxx authentication plaintext-password xxxxxx
set system ntp server xxxxx.tld
set system ntp server xxxxx.tld
set system ntp server xxxxx.tld
set system syslog global facility all level 'info'
set system syslog global facility protocols level 'debug'
set system time-zone 'Asia/Kolkata'
set vpn ipsec esp-group TESTESP compression 'disable'
set vpn ipsec esp-group TESTESP lifetime '28800'
set vpn ipsec esp-group TESTESP mode 'tunnel'
set vpn ipsec esp-group TESTESP pfs 'dh-group5'
set vpn ipsec esp-group TESTESP proposal 10 encryption 'aes256'
set vpn ipsec esp-group TESTESP proposal 10 hash 'sha256'
set vpn ipsec ike-group TESTIKE dead-peer-detection action 'restart'
set vpn ipsec ike-group TESTIKE dead-peer-detection interval '5'
set vpn ipsec ike-group TESTIKE dead-peer-detection timeout '20'
set vpn ipsec ike-group TESTIKE ikev2-reauth 'no'
set vpn ipsec ike-group TESTIKE key-exchange 'ikev2'
set vpn ipsec ike-group TESTIKE lifetime '28800'
set vpn ipsec ike-group TESTIKE proposal 10 dh-group '5'
set vpn ipsec ike-group TESTIKE proposal 10 encryption 'aes256'
set vpn ipsec ike-group TESTIKE proposal 10 hash 'sha256'
set vpn ipsec interface 'eth0'
set vpn ipsec interface 'eth1'
set vpn ipsec options disable-route-autoinstall
set vpn ipsec site-to-site peer xxxxx.tld authentication id 'xxx.xxx.10.100'
set vpn ipsec site-to-site peer xxxxx.tld authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer xxxxx.tld authentication pre-shared-secret xxxxxx
set vpn ipsec site-to-site peer xxxxx.tld authentication remote-id 'xxx.xxx.30.100'
set vpn ipsec site-to-site peer xxxxx.tld connection-type 'initiate'
set vpn ipsec site-to-site peer xxxxx.tld description 'R!-R#'
set vpn ipsec site-to-site peer xxxxx.tld ike-group 'TESTIKE'
set vpn ipsec site-to-site peer xxxxx.tld ikev2-reauth 'inherit'
set vpn ipsec site-to-site peer xxxxx.tld local-address 'xxx.xxx.10.100'
set vpn ipsec site-to-site peer xxxxx.tld vti bind 'vti1'
set vpn ipsec site-to-site peer xxxxx.tld vti esp-group 'TESTESP'