Inspection of IPsec VPN Traffic Overview
Internet Protocol Security (IPsec) virtual private networks use the Encapsulated Security Payload (ESP) protocol and the NULL encryption algorithm to ensure the authenticity, integrity, and confidentiality of IP packets.
To inspect the payload of an encapsulated packet, the IDP process engine must decapsulate it. IDP Series appliances support decapsulation for IPsec ESP NULL traffic. You can configure decapsulation for one or two layers.

