IPsec anti-replay prevents IPsec from replay attacks and improves the reliability of IPsec tunnels.
You can configure the IPsec anti-replay window using either of the following methods:
Global configuration
A globally configured IPsec anti-replay window takes effect on all existing IPsec policies (except those who have local anti-replay windows), and therefore enhances configuration efficiency. You can configure a global parameter for all the IPsec policies that need a same window size instead of manually executing commands for each IPsec policy.
Local configuration
You can set an anti-replay window separately for a single IPsec policy. A separately configured anti-replay window has precedence over the global anti-replay window.
For details about the IPsec anti-replay feature, see Configuring IPsec Security.
To ensure proper service operation, any configuration of the IPsec anti-replay window takes effect only on the IPsec policies being negotiated right after being created or that being renegotiated, but not on the negotiated IPsec policies.