Today I was Billy Big Balls and upgraded a customer from R80.20 to R81.10. All went well, except site-to-site VPN tunnels didn't come back up.
"zdebug" showed outbound IKE dropping on the cleanup rule.
Previously this worked via the Global "Accept outgoing traffic from the gateway" tick box.
This box is still ticked, but doesn't seem to be working... hence maybe this is a bug?
I've added a security rule to allow outbound IKE and the tunnels all came back.
So - one to be aware of if you go to R81.10 and your tunnels stay down.