I read this Google's documentation. This part confuses me.
Each firewall rule applies to incoming (ingress) or outgoing (egress) connection, not both.
Further down the paragraph
VPC firewall rules are stateful.
When a connection is allowed through the firewall in either direction, return traffic matching this connection is also allowed. You cannot configure a firewall rule to deny associated response traffic.
Based on the above, am I right to think that connection and traffic direction are not referring to the same thing?
In GCP, ingress direction is by default. If we don't specify a direction, the firewall rules apply on an instance is applied to only ingress direction. So how does the return traffic match the firewall rule when it is only applied in one direction?