IPSec disconnected after lifetime, takes about two minutes to reconnect

Options
mik256
mik256 Posts: 12
Friend Collector First Comment

I am having an issue where Zyxel initiated IPSec tunnel is periodically disconnected after lifetime period and gets reconnected after about 2 minutes of disruption.

What can I do to have the tunnel stable?

Logs:

2024-04-10 14:55:48 The cookie pair is : 0xd3a7316a7d603621 / 0x5d9704e0306922fd [count=4]
2024-04-10 14:55:48 Send:[HASH][DEL] [count=3]
2024-04-10 14:55:48 ISAKMP SA [mKerioIKEv1] is disconnected


2024-04-10 14:57:37 The cookie pair is : 0xee18ebc0a2e3a3e6 / 0x0000000000000000 [count=3]
2024-04-10 14:57:37 Tunnel [mKerioVPN] Sending IKE request

All Replies

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,101  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @mik256

    You can extend the Phase1 and Phase2 SA life time and verify the VPN connection again.

    The default phase 1 SA life time is 86400 seconds, as shown below:

    The default phase 1 SA life time is 28800 seconds, as shown below:

    Thanks.

  • mik256
    mik256 Posts: 12
    Friend Collector First Comment
    Options

    I have been playing with lifetime for a few weeks now. Trying different combinations on both ends (equal, higher/lower on one side)..

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,101  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @mik256

    Thank you for your comment. Can we check your firewall via the remote Web-GUI? We will send you a private message later, so please check your inbox. Thank you.

Security Highlight