The lifetime values (there are several different values) are not idle timeouts. When they expire it means that new "sa" keys should be exchaned.
There are different timeouts values for isakmp (phase 1) and for ipsec (phase 2).
Does the tunnel drop after 20 minutes of idle, or even when you transfer data it still drops?
Try to use a script or utility (like KIT from my web-site) that will ping every few minutes across the VPN tunnel.
Does it drop now?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.