I have a router with 3 IPsec tunnels configured. Normally everything works as expected, but after few days all 3 tunnels stop at the same time. The only way I can correct the situation is to reboot the router. After the reboot all 3 tunnels are fully functional again.
I can't find any reason for this. My main questions is: how can I find what went wrong when it happens?
On the remote hosts there is nothing unusual in logs. Only entries about expired SAs and new SAs.
The endpoints can ping each other.
There are vaild phase1 (ISAKMP) associations and phase2 (SA) associations as well. They match on both sides. If I reset any of these on the router, new associations will be negotiated within seconds, but it does not help.
Remote osts are sending AH/ESP packets to the router, but no packets are coming from the router.
HW, SW is RB2011UiAS, 6.18. I have just upgraded to 6.19 and I wait for this error to occur again. This may take a week.