Chapter 10 IPsec VPN : Phase 1 parameters : Dynamic IPsec route control : Blocking IPsec SA Negotiation
  
Blocking IPsec SA Negotiation
For interface-based IPsec, IPsec SA negotiation blocking can only be removed if the peer offers a wildcard selector. If a wildcard selector is offered then the wildcard route will be added to the routing table with the distance/priority value configured in Phase 1 and, if that is the route with the lowest distance, it is installed into the forwarding information base.
In cases where this occurs, it is important to ensure that the distance value configured on Phase 1 is set appropriately.