I have configured a tunnel between vyos and Paloalto and Paloalto is behind NAT. Once tunnel is established I am running command “test vpn ike-sa” on Paloalto. Paloalto start creating new child_sa and does not send delete child_sa request for old child_sa. vyos gets new child_sa request and start deleting old child_sa. vyos send delete child_sa request to Paloalto for old child_sa but since Paloalto has already deleted old sa it does not respond to delete request. vyos sends delete request for 5 tumes and deactivate vti0.
I am getting following logs in charon.log:
Jun 14 06:11:41 14[IKE] <peer-10.15.18.12-tunnel-vti|2> giving up after 5 retransmits
Jun 14 06:11:41 14[IKE] <peer-10.15.18.12-tunnel-vti|2> proper IKE_SA delete failed, peer not responding
Jun 14 06:11:41 13[KNL] interface vti0 deactivated
generated by /opt/vyatta/sbin/vpn-config.pl
vyos is in responder mode. how can I make sure that when delete request from vyos does not get responded vti0 should not go down.