The ipsec flow-overlap check enable command enables detection of overlapping IPSec flows.
The undo ipsec flow-overlap check enable command disables detection of overlapping IPSec flows.
By default, detection of overlapping IPSec flows is disabled.
Application Scenarios
In an LTE IPSec scenario, new base stations are usually added during network upgrade and capacity expansion, and the firewall needs to interconnect with these new base stations. In this case, you can enable detection of overlapping IPSec flows so that the device can detect whether to-be-encrypted data flows generated by the new tunnel overlap with existing ones after IKE negotiation. If no, the new tunnel is successfully established. If yes, the new tunnel fails to be established, and the device sends an alarm (IPSEC/4/IPSECTUNNELSTOP) on to-be-encrypted data flow overlapping. This requires you analyze the device networking, and plan and deliver more reasonable ACL configurations.
Precautions