VTI tunnel interface protocol goes DOWN during ipsec re-key
I have routers 2801 and 2921 with IPSec static virtual tunnels (VTI) configured. Sometimes during ipsec re-key goes the VTI tunnel protocol DOWN. ISAKMP and IPSEC SA are OK, elapsed time of both lifetime is same as time from tunnel protocol down. I must reconnect tunnel interface manual with clear crypto sa. Between this routers are only switches of our ISP and optical connections. Ping aren't longer than 40 ms. Do you have any idea why this happened?
IOS version on 2801 is 12.4(9)T5 and on 2921 is 15.2(4)M1. Configuration on the both side is same (except IP addresses). IPSec is in tunnel mode (default settings). I think that this fault is only when ISAKMP timelife expired and have to re-key. On LAN interface I was set ip tcp adjust-mss 1360 in the past.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...