IPsec control packets are generally sent out of any of the egress interfaces based on the ECMP IP route that covers the remote IP address of the IPsec connection. This is not suited in some deployments. For example, when an IPsec end device is establishing connections with another device across more than one ISP (Internet Service Provider) and the control packets may get different NAT treatment based on which ISP they are going over.