Can you tell me:
If you create rules with Source 192.168.0.0/24 and Destination 192.168.20.1/32 it's in two sides or only from src to dst ?
Or need to create second rules which source 192.168.20.1/32 send packages to network 192.168.0.0/24?
yes only 1 way. but almost no traffic/session works without two-way communication. to be sure you can make rules for both sites/subnets.
So if i want that Network see device and device see Network i need to create two rules?
First Rule: Source 192.168.0.0/24 Destanation 192.168.20.20/32
Second Rule: Source 192.168.20.20/32 Destanation 192.168.0.0/24
And doesn't matter if its traffic between VLANs?
Am I right? It's like standard firewall in Iptables and etc