Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
iancollins
Participant
Jump to solution

Site to site vpn drops on policy install

I have about 8 site to site vpn connections to customers on our R80.30 firewall.

When I install policy changes, some of these connections drop out. Using vpn tu option 7 fixes it.
I've seen various discussions about this - but am unsure what to try.

We currently have "rematch connections" in the connections persistence settings. Is this the best setting - or are there any recommendations for "keep data connections" or "keep all connections"?

How about overriding the default settings in the services in the ipsec service group - and setting "Keep connections open after the policy has been installed"?

Thanks, Ian

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

Try setting the keep_IKE_SAs checkbox as described here:

sk142355: VPN tunnel goes down after policy push, must be reset to bring it up

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm

View solution in original post

(1)
1 Reply
Timothy_Hall
Legend Legend
Legend

Try setting the keep_IKE_SAs checkbox as described here:

sk142355: VPN tunnel goes down after policy push, must be reset to bring it up

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events