VPN IPSec Tunnel dropped out after 10-15 minutes

Hi everybody,

I have 3 VPN Tunnels on my VyOS (1.3). everything working fine just one of my VPN tunnels dropped out after some minutes and I must reset the vpn tunnel again and after reset working again but just for 10-15 minutes and dropped out again!

do you have any idea why something like this happening and what is solution ?

I think it’s dropped out because of inactivity! shouldn’t reconnect again ?!

Re-check timers for esp and ike and other vpn configs.
They must be the same on 2 sides.

set vpn ipsec auto-update '60'
set vpn ipsec esp-group ipsec-esp compression 'disable'
set vpn ipsec esp-group ipsec-esp lifetime '86400'
set vpn ipsec esp-group ipsec-esp mode 'tunnel'
set vpn ipsec esp-group ipsec-esp pfs 'disable'
set vpn ipsec esp-group ipsec-esp proposal 1 encryption '3des'
set vpn ipsec esp-group ipsec-esp proposal 1 hash 'md5'
set vpn ipsec esp-group ipsec-esp-link compression 'disable'
set vpn ipsec esp-group ipsec-esp-link lifetime '86400'
set vpn ipsec esp-group ipsec-esp-link mode 'tunnel'
set vpn ipsec esp-group ipsec-esp-link pfs 'dh-group5'
set vpn ipsec esp-group ipsec-esp-link proposal 1 encryption 'aes256'
set vpn ipsec esp-group ipsec-esp-link proposal 1 hash 'sha1'
set vpn ipsec ike-group ipsec-ike dead-peer-detection action 'restart'
set vpn ipsec ike-group ipsec-ike dead-peer-detection interval '15'
set vpn ipsec ike-group ipsec-ike dead-peer-detection timeout '30'
set vpn ipsec ike-group ipsec-ike ikev2-reauth 'no'
set vpn ipsec ike-group ipsec-ike key-exchange 'ikev1'
set vpn ipsec ike-group ipsec-ike lifetime '28800'
set vpn ipsec ike-group ipsec-ike proposal 1 encryption '3des'
set vpn ipsec ike-group ipsec-ike proposal 1 hash 'sha1'
set vpn ipsec ike-group ipsec-ike-link dead-peer-detection action 'restart'
set vpn ipsec ike-group ipsec-ike-link dead-peer-detection interval '15'
set vpn ipsec ike-group ipsec-ike-link dead-peer-detection timeout '30'
set vpn ipsec ike-group ipsec-ike-link ikev2-reauth 'no'
set vpn ipsec ike-group ipsec-ike-link key-exchange 'ikev1'
set vpn ipsec ike-group ipsec-ike-link lifetime '28800'
set vpn ipsec ike-group ipsec-ike-link proposal 1 encryption 'aes256'
set vpn ipsec ike-group ipsec-ike-link proposal 1 hash 'sha1'

do I need to change ? or check with another side first?

At first, the lifetime of “esp” should not be longer than the “ike” lifetime.

can you please help me if I need to edit it ?
I’m not sure how can I edit it!
thanks in davance

Double re-check these timers with a remote site.