VPN up but no traffic after few hours


I have situation where there is VPN connection between Vyos and ISP’s router.
At first the VPN is up, can ping remote prefix (remote prefix is in kernel route) and traffic can go through.

However after few hours (in my current situation 9 to 10hours) the prefix route in kernel is missing. Unable to ping remote prefixes and no traffic going through. The VPN is up with traffic Bytes In/Out shows N/A :

vyos@vyos:~$ sh vpn ipsec sa | strip-private
Connection State Up Bytes In/Out Remote address Remote ID Proposal

peer-xxx.xxx.251.6-tunnel-1 up 44 minutes N/A xxx.xxx.251.6 N/A AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024

I have to restart VPN everytime this issue happen. It start to happen after I upgrade vyos 1.1.8 to 1.2.
Any idea why this is happen?

I noticed the same on my build of 1.2.5 yesterday. I’m trying to see if dead peer detection might be a fix.

Hi @compuwizz

I don’t think dead peer detection can work as both phase 1 and phase 2 peer are not down.
But do tell me if dead peer detection could fix it.

I just put a script to reset the peer if the kernel route missing.
Will monitor it today to see if its working.

Are you using IKEv1? Dead peer detection is a IKEv1 addendum
It is not needed when using IKEv2 (it is built in).

It not using it already, consider switching to IKEv2.

Otherwise you may want to check the lifetime configure in the IKE group and ESP group, and check whether they match those configured on the remote endpoint.

I am using IKE v1 on site to site tunnels. My Phase 2 was originally down when I looked. However after adding dead peer detection, all my vpns have stayed up.


That’s great. Thank for sharing.