The use of null encapsulation is not recommended. It might expose your network to security risks by allowing IP traffic to ...

The use of null encapsulation is not recommended. It might expose your network to security risks by allowing IP traffic to be sent in plaintext, without integrity protection or encryption.

We recommend that you use an option that includes integrity protection or encryption.

Select null encapsulation only if required to support network
devices and software that must be able to inspect network traffic
and that are not compatible with ESP or AH.

Null encapsulation is not compatible with IPsec tunnel mode policies or policies that use a preshared key as the first authentication method.