Is anyone currently using IKEv2 non-Meraki IPSectunnels between Meraki MX and SonicWall TZ? How's your experience? For me, I am having a mysterious stability issue with IPSec.
My environment:
I have 3 sites, let's say site A and B. They are using Meraki MX84 connected to each other with Meraki AutoVPN. Site C is using SonicWall TZ270 and connected to both A and B using IKEv2 non-Meraki IPSec with AES256, SHA256 proposals. Lifetime is 86400 for Phase 1 and 43200 for Phase 2. I use networks tags with IPSec settings in both Meraki networks.
My issue:
I cannot reach from C to A, C to B and vice versa intermittently though both Meraki dashboard and SonicWall GUI are showing that the tunnel is up and green. But I cannot ping, http or smb to my servers in A and B. There is no obivious warning or error logs as well in all sites. Meraki support cannot find in their backend logs too. The time of issue occurence in 2 tunnels are also different. Sometimes, only a few subnets are unreachable while I can reach to others from the same VPN rule. This keeps happening like every day.
My current workaround:
Everytime I have the issue, I have to disable and re-enable the VPN rules from my SonicWall site to re-establish the VPN immediately without waiting for the lifetime to expire.
My findings in logs:
While I am having the issue, the only log I can notice is that SA to site C are established last 12 hours ago. But there is no SA closing log before re-establishing a new one when the life time expires. Once expired, the tunnels automatically re-negotiates and I can reach to my servers in A or B again. But I really don't know the time when the next issue will occur again.
My work with Meraki and SonicWall support:
They ask me to call them whenever I have the issue without restarting the VPN as per my mentioned workaround.
Has anyone experienced the same as me before? Or is it just that SonicWall is kinda having issue with Meraki?