Chapter 11 IPsec VPN for FortiOS 5.0 : Phase 2 parameters : Advanced phase 2 settings : Replay detection
  
Replay detection
IPsec tunnels can be vulnerable to replay attacks. Replay detection enables the FortiGate unit to check all IPsec packets to see if they have been received before. If any encrypted packets arrive out of order, the FortiGate unit discards them.