I just wanted to chime in here with a "me too" Merak end: MX84, version 14.40 Cisco end: ASA 5585, version 9.8.4(10) For two weeks i've been having to re-type a PSK on both Meraki and Cisco ASA side to get the tunnel to come back up. My settings were: IKE Policy: AES 256, SHA1, 86400 lifetime IPSEC Proposal: AES 256, SHA1, 86400 lifetime Problem: Tunnel drops right at 18 hours. I had Meraki turn off NAT-T -- this did not fix the issue. I then made the following changes: IKE: 3DES, SHA1, lifetime 3600 IPSEC: 3DES, SHA1, lifetime 3600 NAT-T turned off still Tunnel has been up for 20+ hours with no drop. I'm assuming its the lifetime values and not the IKE/IPSEC proposals. At any rate after struggling through this for weeks i'm happy it seems to be working better now. Skip
... View more