I have several VPNs against AWS, it happens that at random there is no more traffic.
When the fault occurs, there are the following symptoms:
-Up Tunnel
-Phase 1 and Phase 2 established
The problem is resolved when we restart Ike at the checkpoint (vpn tu - 7), but after a while it happens again. The configuration of my Tunnel is as follows:
IKv1 Phase I.
-Encryption Algorithm: AES-128
-Data Integrity: SHA1
Diffie-Hellman group: Group 2 (1024bit)
Phase II -AES-128
Data Integrity: SHA1
IKE Security Association (Phase2): Use perfect Forward Secrecy (group 2)
Ike Phase I.
Renegotiate IKE Security associations every (minutes): 480
IPsec (Phase 2):
Renegotiate IPsec security associations every (seconds): 3600 Nat: Disable NAT inside the VPN community
DPD configured in the Cluster and AWS Community VPI and Ping interfaces on static routes
Tunnel Management
-Permanent tunnels: establish permanent tunnels: in all the tunnels of the community.
-VPN Tunnel Sharing: One VPN tunnel per Gateway pair. VPN ROUTING: to center or, even the center, other satellites, the Internet and other VPN objectives
DPD configured in the Cluster and AWS Community VPI and Ping interfaces on static routes
when I see the records, it's dropping by rule clean up
please your support, the tac still does not find the cause