Hi Uwe
I have in my settings to multiple site2site tunnels put ike rekey to 3600 sec (60 minuts) and ipsec rekey to 3600 sec.
I would check ike Phase 1 and ipsec phase 2 are the same.
Also found out to disable dead peer detection (dpd) keepalive on Cisco router/firewall
I often use from expert mode ssh to gwcluster active node or cluster ip addr
vpn tu
To reset vpn tunnel I use option 7
Check if IKE phase 1 have been establish option 3
Check if Ipsec phase 2 have been establish option 4
To check tunnel list
vpn tu tlist -p <remote peer address>
I hope that could help your search for help
Best regards
Kim
Best Regards
Kim