Hi, guys.
We have a VPN site to site mounted against Azure, the problem we are not finding is that this VPN drops every 8 hours, after opening case with microsoft, I recommended lowering the time of phase 1 a few minutes so that it was the checkpoint side that performed the rekey, but the problem has not been solved, you keep losing the VPN every 8 hours. It could occur to you what may be going on?, it could make some change to the VPN on the checkpoint side.
The FW model is 1800 smb with embedded gaia 80.20.35, there may be some limitations here. In the checkpoint tacker I don't see anything in the logs.
The tunnel is configured in one VPN tunnel per Gateway pair
Phase 1 480 minutes. Phase 2 27000 seconds.
And this is what Microsoft tells me to look at on the checkpoint side, but I don't know what it means.
"No Additional SAs"
"Reached maximum quick mode limit for the main mode. New main mode will be started."
Azure Comments
Every time the MM expires and Azure initiates an rekey the peer devices send a response that no additional SA’s are available ( maximum limit reached) and as a results the old tunnel is closed and a new tunnel is build.
This tunnel is not using Traffic selectors so only 1 IKE SA is negotiated for 0.0.0.0.0/0 :
Please check remote vpn device configuration ; Why it replies that the maximum QM SA’s is reached . Check with their support also if needed.
I think I will open a case with support, but any help is welcome, if it occurs to you that it may be happening.
Thankss¡¡.