The policies in this group allow only existing WAN connections to be used but assumes that a connection that hasn't been used for 15 minutes is being spoofed and should not be used. There are two policies.
This policy prevents the checking of backlinks, external references, and login restrictions, the running of janitor or limber, and schema synchronization except on existing WAN connections that have been open less than 15 minutes. Compare Already Open, No Spoofing.
This policy prevents other traffic to existing WAN connections that have been open less than 15 minutes. Compare Already Open, No Spoofing, NA.
To prevent all traffic to existing connections open less than 15 minutes, both policies must be applied.