IPSec disconnected after lifetime, takes about two minutes to reconnect

mik256
mik256 Posts: 12
First Comment Friend Collector

I am having an issue where Zyxel initiated IPSec tunnel is periodically disconnected after lifetime period and gets reconnected after about 2 minutes of disruption.

What can I do to have the tunnel stable?

Logs:

2024-04-10 14:55:48 The cookie pair is : 0xd3a7316a7d603621 / 0x5d9704e0306922fd [count=4]
2024-04-10 14:55:48 Send:[HASH][DEL] [count=3]
2024-04-10 14:55:48 ISAKMP SA [mKerioIKEv1] is disconnected


2024-04-10 14:57:37 The cookie pair is : 0xee18ebc0a2e3a3e6 / 0x0000000000000000 [count=3]
2024-04-10 14:57:37 Tunnel [mKerioVPN] Sending IKE request

All Replies

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,251  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    Hi @mik256

    You can extend the Phase1 and Phase2 SA life time and verify the VPN connection again.

    The default phase 1 SA life time is 86400 seconds, as shown below:

    The default phase 1 SA life time is 28800 seconds, as shown below:

    Thanks.


    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

  • mik256
    mik256 Posts: 12
    First Comment Friend Collector

    I have been playing with lifetime for a few weeks now. Trying different combinations on both ends (equal, higher/lower on one side)..

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,251  Zyxel Employee
    100 Answers 500 Comments Friend Collector Fourth Anniversary

    Hi @mik256

    Thank you for your comment. Can we check your firewall via the remote Web-GUI? We will send you a private message later, so please check your inbox. Thank you.


    See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community

Security Highlight