Hi Spuluka!
First of all, big thanks to your reply!
Great references and explanation!
I can confirm that the configs are the same on the devices and it's phase 2 thats going down.
When the ICMP replies stops i can no longer see the following:
<268173313 ESP:3des/sha1 XXXXXXX 3531/ unlim U root 500 95.192.214.166
>268173313 ESP:3des/sha1 XXXXXXX 3531/ unlim U root 500 95.192.214.166
And i get the following messages from the log config you sent:
Oct 7 09:42:06 JRF-SW03 kmd[1427]: KMD_VPN_DOWN_ALARM_USER: VPN instance-STHLARM_268173313 from 95.192.214.166 is down. Local-ip: 212.112.166.157, gateway name: gw_STHLARM, vpn name: STHLARM, tunnel-id: 268173313, local tunnel-if: st0.11, remote tunnel-ip: Not-Available, Local IKE-ID: 212.112.166.157, Remote IKE-ID: larm-branch, XAUTH username: Not-Applicable, VR id: 0, Traffic-selector: , Traffic-selector local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Traffic-selector remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0)
Oct 7 09:42:36 JRF-SW03 kmd[1427]: KMD_PM_SA_ESTABLISHED: Local gateway: 212.112.166.157, Remote gateway: 95.192.214.166, Local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Direction: inbound, SPI: 0xfc2742ca, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector:
Oct 7 09:42:36 JRF-SW03 kmd[1427]: KMD_PM_SA_ESTABLISHED: Local gateway: 212.112.166.157, Remote gateway: 95.192.214.166, Local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Direction: outbound, SPI: 0xd5fe95ac, AUX-SPI: 0, Mode: Tunnel, Type: dynamic, Traffic-selector:
Oct 7 09:42:36 JRF-SW03 kmd[1427]: KMD_VPN_UP_ALARM_USER: VPN instance-STHLARM_268173313 from 95.192.214.166 is up. Local-ip: 212.112.166.157, gateway name: gw_STHLARM, vpn name: STHLARM, tunnel-id: 268173313, local tunnel-if: st0.11, remote tunnel-ip: Not-Available, Local IKE-ID: 212.112.166.157, Remote IKE-ID: larm-branch, XAUTH username: Not-Applicable, VR id: 0, Traffic-selector: , Traffic-selector local ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0), Traffic-selector remote ID: ipv4_subnet(any:0,[0..7]=0.0.0.0/0)
How can i get further information about the reason for it going down and then immediatly up again?