I dont believe its Cisco side. Here are drops on CP end when issue is happening:
# fw ctl zdebug + drop | grep 205.207.130.253
@;127721520;[cpu_0];[SIM-204987365];sim (vpn_encrypt): drop due vpn_ipsec_encrypt returns PKT_DROP(3), conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127721520;[cpu_0];[SIM-204987365];handle_vpn_encryption: ipsec_encrypt failed: failed to find SA. Dropping packet... conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127721520;[cpu_0];[SIM-204987365];sim_pkt_send_drop_notification: (0,1) received drop, reason: Encryption Failed, conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127721520;[cpu_0];[SIM-204987365];sim_pkt_send_drop_notification: sending packet dropped notification drop mode: 0 debug mode: 1 send as is: 0 track_lvl: -1, conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127721520;[cpu_0];[SIM-204987365];sim_pkt_send_drop_notification: sending single drop notification, conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127721521;[cpu_0];[SIM-204987365];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:<172.16.193.243,50846,205.207.130.253,22,6>;
@;127722353;[cpu_0];[SIM-204987365];sim (vpn_encrypt): drop due vpn_ipsec_encrypt returns PKT_DROP(3), conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127722353;[cpu_0];[SIM-204987365];handle_vpn_encryption: ipsec_encrypt failed: failed to find SA. Dropping packet... conn: <172.16.193.243,50846,205.207.130.253,22,6>;
@;127722353;[cpu_