Why the site-to-site VPN tunnel will disconnect hourly? How to reslove it?

Options
Zyxel_Jeff
Zyxel_Jeff Posts: 1,083  Zyxel Employee
First Anniversary 10 Comments Friend Collector First Answer
edited April 3 in VPN

Scenario :

Users may encounter a situation in the site-to-site VPN tunnel that will disconnect hourly. This article will guide you on how to identify the possible reasons and resolve this problem.

Answer :

The possible reason for the site-to-site VPN disconnecting hourly is that the Phase 2 SA Lifetime is set to 3600 seconds. When it reaches 3600 seconds, the firewall initiates a re-key process, causing the site-to-site VPN to disconnect.

The acceptable solution is to extend the SA Lifetime, as shown below. The SA Lifetime is extended to the default value of 28800 seconds (which equals 8 hours).