Why the site-to-site VPN tunnel will disconnect hourly? How to reslove it?

Zyxel_Jeff
Zyxel_Jeff Posts: 1,316  Zyxel Employee
100 Answers 500 Comments Friend Collector Fourth Anniversary
edited April 2024 in VPN

Scenario :

Users may encounter a situation in the site-to-site VPN tunnel that will disconnect hourly. This article will guide you on how to identify the possible reasons and resolve this problem.

Answer :

The possible reason for the site-to-site VPN disconnecting hourly is that the Phase 2 SA Lifetime is set to 3600 seconds. When it reaches 3600 seconds, the firewall initiates a re-key process, causing the site-to-site VPN to disconnect.

SA 3600.png

The acceptable solution is to extend the SA Lifetime, as shown below. The SA Lifetime is extended to the default value of 28800 seconds (which equals 8 hours).

SA 28800.png