Dear Team
We have 3 Different location and we are connected all 3 Different via Ipsec tunnel.
We have created IPsec through BGP and also run VRRP for gateway failover and after every 10 to 15 days my tunnel getting down.
Below are the IPs configured on my interface and iam using vyos 1.2.0 version
Interface IP Address S/L Description
eth0 172.17.40.161/16 u/u BLUE Management Network
eth1 192.168.161.1/24 u/u RED Public Network
eth1v161 43.224.129.92/24 u/u
eth2 10.10.1.2/24 u/u GREEN Lan Network
eth2v161 10.10.1.1/24 u/u
lo 127.0.0.1/8 u/u
::1/128
vti10 192.168.11.1/30 u/u
vti20 192.168.10.1/30 u/u
vtun0 10.34.1.1/24 u/u
vtun1 10.34.2.1/24 u/u
Vti10 is used for one location and vti20 is used for other location connectivity and every time when tunnel goes down this interfaces showing disable
below are my Ipsec Configuration :-
set vpn ipsec esp-group i2k2_2_ESP compression ‘disable’
set vpn ipsec esp-group i2k2_2_ESP lifetime ‘3600’
set vpn ipsec esp-group i2k2_2_ESP mode ‘tunnel’
set vpn ipsec esp-group i2k2_2_ESP pfs ‘enable’
set vpn ipsec esp-group i2k2_2_ESP proposal 1 encryption ‘aes256’
set vpn ipsec esp-group i2k2_2_ESP proposal 1 hash ‘sha1’
set vpn ipsec esp-group i2k2_3_ESP compression ‘disable’
set vpn ipsec esp-group i2k2_3_ESP lifetime ‘3600’
set vpn ipsec esp-group i2k2_3_ESP mode ‘tunnel’
set vpn ipsec esp-group i2k2_3_ESP pfs ‘enable’
set vpn ipsec esp-group i2k2_3_ESP proposal 1 encryption ‘aes256’
set vpn ipsec esp-group i2k2_3_ESP proposal 1 hash ‘sha1’
set vpn ipsec ike-group i2k2_2_IKE dead-peer-detection action ‘restart’
set vpn ipsec ike-group i2k2_2_IKE dead-peer-detection interval ‘30’
set vpn ipsec ike-group i2k2_2_IKE dead-peer-detection timeout ‘40’
set vpn ipsec ike-group i2k2_2_IKE ikev2-reauth ‘no’
set vpn ipsec ike-group i2k2_2_IKE key-exchange ‘ikev1’
set vpn ipsec ike-group i2k2_2_IKE lifetime ‘28800’
set vpn ipsec ike-group i2k2_2_IKE proposal 1 dh-group ‘2’
set vpn ipsec ike-group i2k2_2_IKE proposal 1 encryption ‘aes256’
set vpn ipsec ike-group i2k2_2_IKE proposal 1 hash ‘sha1’
set vpn ipsec ike-group i2k2_3_IKE dead-peer-detection action ‘restart’
set vpn ipsec ike-group i2k2_3_IKE dead-peer-detection interval ‘30’
set vpn ipsec ike-group i2k2_3_IKE dead-peer-detection timeout ‘40’
set vpn ipsec ike-group i2k2_3_IKE ikev2-reauth ‘no’
set vpn ipsec ike-group i2k2_3_IKE key-exchange ‘ikev1’
set vpn ipsec ike-group i2k2_3_IKE lifetime ‘28800’
set vpn ipsec ike-group i2k2_3_IKE proposal 1 dh-group ‘2’
set vpn ipsec ike-group i2k2_3_IKE proposal 1 encryption ‘aes256’
set vpn ipsec ike-group i2k2_3_IKE proposal 1 hash ‘sha1’
set vpn ipsec ipsec-interfaces interface ‘eth1v161’
set vpn ipsec site-to-site peer 103.239.129.10 authentication id ‘43.224.129.92’
set vpn ipsec site-to-site peer 103.239.129.10 authentication mode ‘pre-shared-secret’
set vpn ipsec site-to-site peer 103.239.129.10 authentication pre-shared-secret ‘C@t@i2k2’
set vpn ipsec site-to-site peer 103.239.129.10 connection-type ‘initiate’
set vpn ipsec site-to-site peer 103.239.129.10 default-esp-group ‘i2k2_3_ESP’
set vpn ipsec site-to-site peer 103.239.129.10 ike-group ‘i2k2_3_IKE’
set vpn ipsec site-to-site peer 103.239.129.10 ikev2-reauth ‘yes’
set vpn ipsec site-to-site peer 103.239.129.10 local-address ‘43.224.129.92’
set vpn ipsec site-to-site peer 103.239.129.10 vti bind ‘vti20’
set vpn ipsec site-to-site peer 103.239.129.10 vti esp-group ‘i2k2_3_ESP’
set vpn ipsec site-to-site peer 203.95.225.10 authentication id ‘43.224.129.92’
set vpn ipsec site-to-site peer 203.95.225.10 authentication mode ‘pre-shared-secret’
set vpn ipsec site-to-site peer 203.95.225.10 authentication pre-shared-secret ‘C@t@i2k2’
set vpn ipsec site-to-site peer 203.95.225.10 connection-type ‘initiate’
set vpn ipsec site-to-site peer 203.95.225.10 default-esp-group ‘i2k2_2_ESP’
set vpn ipsec site-to-site peer 203.95.225.10 ike-group ‘i2k2_2_IKE’
set vpn ipsec site-to-site peer 203.95.225.10 ikev2-reauth ‘yes’
set vpn ipsec site-to-site peer 203.95.225.10 local-address ‘43.224.129.92’
set vpn ipsec site-to-site peer 203.95.225.10 vti bind ‘vti10’
set vpn ipsec site-to-site peer 203.95.225.10 vti esp-group ‘i2k2_2_ESP’
When I run " restart vpn " command , the tunnel become UP and working fine but why every time i need to run this command , its haqtique for me everytime.
Please suggest what else i need to configure so that this issue will be resolved