Rodney, The window size of 1 does prevent replay, but it also prevents legitimate, out-of-order arrival of packets at the IP layer. A larger window size does not allow ANY replays; it just allows packets to arrive at the IPsec implementation out of order and still be checked and accepted. Steve