The current conf has a statement of "set sec flo tc-ms all-tcp mss 1430. But I want to assign a more specific tcpmss value for the IPsec traffic on the srx device, so I will use "set sec flo tc-mss ipsec-vpn mss <value>". In this case what should I do with ""set security flow tcp-mss all-tcp mss 1430". Should I leave what it is.... Or must it be removed from before assigning a tcpmss value for the ipsec-vpn traffic. Or does it no matter to use both? Or which one overrides? What is best practice when having both IPsec traffic and non-IPsec traffic on the same srx box?