BUG was found. IPsec works not stable

There are several tunnels IPsec. Regardless of time and without changing any settings tunnels stop working.
In the settings you can see that the key exchange in one direction occurs, but the traffic flow is not (IP->IPsec->Installed SAs->some key->Current Bytes=0).
After several reboots tunnel restored. After spending some time again stops working.
Fix please!
Remote office work impossible. Business idle incur losses

RouterOS - v6.15/6.14
HW - CCR1036-12G-4S, RB2011UiAS, RB951G-2HnD, RB2011UiAS-2HnD

I updated every 6.15.
6.15 between the same problem.

Duplicate topic? Have you sent message to support?

Sute on a separate issue. I really left the same message in another topic. But it is to discuss the new version. Yes, I sent a message to support.

set a ping script like

/ping <remote private IP> src-address=<local private IP> count=10

and run it every 5 minutes or so…

I’ve had the same issue when there was no traffic through the tunnels and that sorted it

cheers

Thank you. But this is not the solution. Tunnel should work without this script. If the tunnel is too much is not the solution …

you’ll be surprised… I’ve seen IPsec tunnels behaving the same even with cisco gear…

it might not be “the solution” but it can be “a solution” :slight_smile:

cheers

Well, this is by ‘design’ and not a bug. You should explicitly take precautions to keep the tunnel up. On Juniper and Cisco you need to do the same thing.
An IPSEC tunnel only stays up when there is traffic.

Yes, IPsec tunnel stays down if there is no traffic. But he must stays up if traffic starts. And sometimes it does not. That’s what I wrote in my problem.

So my problem is different. I have the traffic (netwatch) and the tunnel was down for two days with no evident reason. Suddenly it went up.

What was the ticket number?

Ticket#2014062566000221

Error repeated exactly. Sending log files. The tunnel not up.
Fix please!