Cisco <=> Cisco | Tunnel UP, but no traffic pass until "reset vpn ipsec peer" on vyos side

Hi, @alabarym!

NAT in the middle or even different paths in two directions are not problems by themselves. However, in some cases - for example, when IPSec peers are not able to detect NAT in the middle - you may get into the situation when an IPSec connection is killed by a NAT device due to inactivity. This is pretty similar to the problem description.

Another potential issue is mentioned by @acrane DH group usage. When PFS settings for Phase 2 are not equal, a tunnel will go down after the first ESP rekeying. So, you should pay attention to this too, because in the Cisco config we do not see PFS settings for Phase 2. Thus you should check default values for this.