Once this started happening, the encpryption (or rather the ability to decrpyt) between group members simply stopped with the next change of keys.
All group memebers are still active participants in the GDOI VPN, they just can't encypt or decrpyt targeted traffic sucessfully (so they are registered with the keyserver, and have the current service policy etc).
The only way to get the group memeber to properly participate in the mesh again is to reload it, which isn't the ideal fix obviously.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...