Hey all,
I have a strange IPSEC/ Site-to-Site VPN issue.
Initial a VPN tunnel works from Meraki MX to Sophos XGS.
After Phase 1 lifetime is reached, only one SA is alive, others are gone.
Restarting the tunnel helps until lifetimes ends.
The tunnel is not getting ready/active when new traffic is generated.
Please do not wonder why my lifetimes are that low. I had issues with tunnel with 28800 seconds. Troubleshooting was really time consuming, so I changed multiple times to lower values.
I have other tunnels to Azure with multiple networks, and this tunnel(s) are working.
Azure <-> Meraki
Azure <-> Sophos XGS
Meraki <-> Sophos XGS (not working)
EDIT: I was using IKEv2....
To avoid conflicts I have also created fake VLANs on my Meraki site.
First screenshot. After enabling the tunnel

Second screenshot: After 10 minutes when Phase 1 has ended

Sophos IKEv2 settings

Meraki IKEv2 settings
