said by markku:
Unfortunately I have to agree with you on having a "always-on" connection does not work between BEFSX/BEFVP41-boxes.
Just ( again ) studied the VPN-logs and saw following. The lifetime of the tunnel is 28800 seconds, however after 5 seconds the tunnel will time out.
[ log data deleted... ]
I have accumulated and studied days and days of logs, and what you see is actually normal behavior. You need to pay attention to the SPI numbers in the DELETE messages. Right after creating a new ESP_SA, the routers delete the
previous one. Likewise for ISAKMP exchanges.
That said, I also see cases where a new ISAKMP forces the current (and possibly just created) ESP_SA to be deleted. However, a replacement is created soon afterwards. Since the ESP_SA key is dependent on the ISAKMP value, this makes sense.