Hi
I have an IPSec VPN between two vyos vms version VyOS 1.4-rolling-202201080317
Every so often the VPN disconnects and resetting the VPN from both ends, fails with
vyos@peer-2:~$ reset vpn ipsec-peer peer-1-ip
Timed out while resetting peer_peer-1-ip_vti
Peer reset result: failed
vyos@peer-2:~$ reset vpn ipsec-peer peer-1-ip
Timed out while resetting peer_peer-1-ip_vti
Peer reset result: failed
This is sometimes mitigated by first running restart vpn
and then attempting a reset after.
Could this be a problem with my configuration, or something else?
Would really appreciate some insights.
My configs are:
peer-2
set vpn ipsec esp-group esp-vyos0 compression ‘disable’
set vpn ipsec esp-group esp-vyos0 lifetime ‘3600’
set vpn ipsec esp-group esp-vyos0 mode ‘tunnel’
set vpn ipsec esp-group esp-vyos0 pfs ‘dh-group19’
set vpn ipsec esp-group esp-vyos0 proposal 10 encryption ‘aes256gcm128’
set vpn ipsec esp-group esp-vyos0 proposal 10 hash ‘sha256’set vpn ipsec ike-group ike-vyos0 dead-peer-detection action ‘restart’
set vpn ipsec ike-group ike-vyos0 dead-peer-detection interval ‘30’
set vpn ipsec ike-group ike-vyos0 dead-peer-detection timeout ‘120’
set vpn ipsec ike-group ike-vyos0 ikev2-reauth ‘no’
set vpn ipsec ike-group ike-vyos0 key-exchange ‘ikev2’
set vpn ipsec ike-group ike-vyos0 lifetime ‘10800’
set vpn ipsec ike-group ike-vyos0 mobike ‘disable’
set vpn ipsec ike-group ike-vyos0 proposal 10 dh-group ‘19’
set vpn ipsec ike-group ike-vyos0 proposal 10 encryption ‘aes256gcm128’
set vpn ipsec ike-group ike-vyos0 proposal 10 hash ‘sha256’
set vpn ipsec site-to-site peer peer-1-ip ike-group ‘ike-vyos0’peer-1
set vpn ipsec ike-group ike-vyos1 dead-peer-detection action ‘restart’
set vpn ipsec ike-group ike-vyos1 dead-peer-detection interval ‘30’
set vpn ipsec ike-group ike-vyos1 dead-peer-detection timeout ‘120’
set vpn ipsec ike-group ike-vyos1 ikev2-reauth ‘no’
set vpn ipsec ike-group ike-vyos1 key-exchange ‘ikev2’
set vpn ipsec ike-group ike-vyos1 lifetime ‘10800’
set vpn ipsec ike-group ike-vyos1 mobike ‘disable’
set vpn ipsec ike-group ike-vyos1 proposal 10 dh-group ‘19’
set vpn ipsec ike-group ike-vyos1 proposal 10 encryption ‘aes256gcm128’
set vpn ipsec ike-group ike-vyos1 proposal 10 hash ‘sha256’
set vpn ipsec site-to-site peer peer-2-ip ike-group ‘ike-vyos1’set vpn ipsec esp-group esp-vyos1 compression ‘disable’
set vpn ipsec esp-group esp-vyos1 lifetime ‘3600’
set vpn ipsec esp-group esp-vyos1 mode ‘tunnel’
set vpn ipsec esp-group esp-vyos1 pfs ‘dh-group19’
set vpn ipsec esp-group esp-vyos1 proposal 10 encryption ‘aes256gcm128’
set vpn ipsec esp-group esp-vyos1 proposal 10 hash ‘sha256’
set vpn ipsec site-to-site peer peer-2-ip default-esp-group ‘esp-vyos1’
set vpn ipsec site-to-site peer peer-2-ip vti esp-group ‘esp-vyos1’