You are right. SA expires before rekey. Set pfs to none and will monitor..Yes, they establish correctly. But do they rekey without issue? Have a look at your log...Thats odd - I've got pfs set in phase 2 and the IKEv2 tunnel establishes correctly: