This really is quite cool feature ..... </end of irony>
from what we saw, it blocks traffic which have same source and destination port numbers .... especially UDP datagrams, so it's breaking things like NTP servers sync, asterisk trunk etc......
we turned that off after we spend like 3 days to investigate ..... burn that checkbox....