Hi,
ESP/AH replay protection is used to prevent attacker from replaying old packets into the IPsec tunnel.
It is implemented by not dropping ESP/AH packets that have sequence numbers older than last packet's sequence number - 32.
When no-replay is set then tunnel will not be protected from replaying ESP/AH packets.
You may want to set no-replay option when you have packet reordering in your network.
For example due to QoS.
Hope this helps.
Kind Regards,
Nemanja