1. Fortinet. (2022). SD-WAN for FortiOS 7.2 Study Guide. Page 100, "Dual hub (hub and spoke)" section. The guide states, "On both hubs, you must disable anti-replay in the phase 2 configuration for the ADVPN tunnel. This is required because traffic can switch between hubs, and the sequence number check will fail."
2. Fortinet. (2022). FortiOS 7.2.0 Administration Guide. In the "IPsec VPN" chapter, the description of phase 2 settings clarifies that anti-replay is an IPsec function to protect against the retransmission of packets. Its disablement is a known requirement for certain asymmetric routing scenarios, such as dual-hub SD-WAN.
3. Fortinet. (2022). FortiOS 7.2.0 CLI Reference. Volume 2, page 1738. The command set replay {enable | disable} under config vpn ipsec phase2-interface is documented as enabling or disabling IPsec SA replay detection, confirming it relates to the IPsec tunnel, not directly to TCP.