Hi ,
I would like to start off by stating that I'm a complete noob when it comes to VPN , IPSEC , SA , IKEv2 and all that stuff.
We have a simple setup. One MX peering to a Palo Alto.
Phase 1 works fine and Phase 2 works fine.... most of the time.
As you can see ( even if it's blured ) there are like 10 subnets configured.
When we establish the tunnel , ALL 10 subnets are working fine. After couple hours ( something like 6-24 hours ). Some of the subnets stop working.
I can see the log on the MX that : msg: <remote-peer-2|13> closing CHILD_SA net-2{42} with SPIs cccdb01e(inbound) (54640 bytes) 9812d7e5(outbound) (144750 bytes) and TS XXXXXXXX/28 === XX.XX.15.0/24
However when ever I try to bring the SA up by sending traffic to .15.0/24 it doesn't. Either I have to bring to whole tunnel down and up OR I can bring it up by sending traffic from the Palo-Alto side.
I have confirmed that the timers of Phase 1 and 2 are matching on both sides ( 28800s and 3600s )
I'm running MX18.211.3 and I have a case open.
I have read the multiple posts here and many of the documentation pages but I couldn't find anything except : https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings#NOTE_For_IKEv2
Any troubleshooting ideas ?
Cheers ,