Hi,
After upgrade from 1.1.8 to 1.3.6, I found that the vpn ipsec policy based are not so stable. After setting up DPD its seems much more stable.
However, when I run command show vpn ipsec sa, all tunnels shows down but I can actually ping the peer prefix.
vyos:~$ sh vpn ipsec sa
Connection State Uptime Bytes In/Out Packets In/Out Remote address Remote ID Proposal
----------------------------- ------- -------- -------------- ---------------- ---------------- ----------- ----------------------------------
peer-203.x.x.x-tunnel-3 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-4 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-5 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-6 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-7 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-8 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-9 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-12 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-13 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-14 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-15 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-16 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-17 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-18 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-19 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-30 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-31 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-32 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-33 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-34 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-35 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-36 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-37 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-38 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-40 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-41 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-42 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-43 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-50 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-51 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-52 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-53 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-60 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-61 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-72 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-73 down N/A N/A N/A N/A N/A N/A
peer-203.x.x.x-tunnel-74 down N/A N/A N/A N/A N/A N/A
Why the tunnels are down but I can ping tunnel remote prefix?