I've got a FreeBSD setup running with three IPSec tunnels (these were created following the official FreeBSD documentation).
The three links have been running fine for many months now, however, I'm regularly getting entries in my /var/log/messages file stating "kernel: esp_input: packet replay check for SA(SPI= src= dst=)".
Depending on the day, these are coming anywhere between 5-30 minutes apart. I suppose it wouldn't be uncommon to see the odd packet reach a destination out of order after traveling around the world. What seems strange is their frequent regularity. The links are stable, but the messages are appearing for each of the tunnels.
Any ideas what could be causing this?