I have five Draytek 2960 running IPSec VPNs to a Sophos XG230.
The Drayteks initiate the connection using IKE2.
I get an email from the Drayteks every 53 minutes saying the link dropped. (It reconnects.) IKE Phase 1 timeout is 28800 seconds, Phase 2 is 3600 seconds on the Drayteks. On the XG, it's 5400 and 3600.
I changed IKE Phase 2 on the Draytek to 7200 seconds. It still drops after 53 minutes.
I disabled Dead Peer Detection on the XG (it's a VPN server, the Drayteks initiate the connection). The VPN dropped and wouldn't connect until I enabled it.
I disabled "Re-key connection" on the XG. The VPN dropped and wouldn't connect until I enabled it.
I changed IKE Phase 2 on the XG to 28800. The VPN dropped and wouldn't connect until I changed it back to 5400.
How do I stop the VPN dying every 53 minutes?
This thread was automatically locked due to age.