[strongSwan] IPSEC IKEv2 disconnecting after ~8 hours - Windows 10 Client

Tobias Brunner tobias at strongswan.org
Mon Jan 17 14:50:02 CET 2022


Hi Ed,

> I did change ikelifetime to 360m (6 hrs) but i 
> am still having issues. Could that still be the cipher?

No, you want to disable reauthentication (reauth=no) so the IKE_SA is 
actually rekeyed to avoid this error:

> These are the logs after modifying ikelifetime so thst the strongswan 
> server initiates the rekey before windows ->
> 
>>     charon: 06[IKE] initiator did not reauthenticate as requested____
>>
>>     charon: 06[IKE] IKE_SA VPN_x_xxxx[71277] will timeout in 3 minutes____

A related ticket can be found at [1].

Regards,
Tobias

[1] https://wiki.strongswan.org/issues/3400


More information about the Users mailing list