When the packet goes to outbound direction there are some action also take place such as packet matches a crypto ACL entry and is clear text then the packet is protected by IPSec. When packet matches a crypto ACL entry and is already protected then the packet protected again by IPSec and the another action is when the packet doesn’t match a crypto ACL (clear text or already protected) then the packet is ignored by IPSec
Fig 5.1 Inbound packet format
Fig 5.2 Outbound packet format