Security considerations of Replay Windows
The window mechanism only allows a limited replay on a user's most recently entered OTP. So no matter what the size of your replay window you need not be concerned about previously-entered OTPs being used again maliciously. Only the freshest, most recently entered OTP is allowed to authenticate repeatedly during the window, and as soon as the user enters a new OTP any time remaining on the old window is canceled.
A short replay window such as 10-20 seconds does not notably diminish the security of an OTP system against most types of attacks. However if an adversary can launch immediate parallel sessions from your machine or in some automated, instantaneous fashion, then any replay window at all can allow impersonation. If you are not using any multiple-authentication protocols with AuthLite you can run without any replay windows configured, disabling this behavior completely.