For some reason, my IPSec connection fails and go down several times a day. The IKE remains UP. Do you know why this could happen? How can I troubleshoot this behaviour please?
Then phase1 stays up for 24h , and phase2 only for single hour.
afaik, a new phase2 session should start, before old one expires. So timers are OK.
Phase1 shows as up, but is it? DPD can detect if it really is. Try enabling it
Setting to 8 hours makes issue less prominent, as phase2 now is up way longer, resulting in less complaints.
Maybe for some reason setup of tunnel only works one-way.
As workaround , forcing one side responder, the other initiator can help.