Hello infotech, Can you try clearing the specific ike-sa and ipsec-sa. Use the commands below : - clear vpn ike-sa gateway <name> - clear vpn ipsec-sa tunnel <name> Then try and clear the specific vpn flow by using the command: - clear vpn flow name <flow name> Clear the ipsec-esp sessions on the firewall as well using the command: - clear session all filter protocol 50 (or) clear session all filter application ipsec-esp Note that above command will clear all the IPsec flows. If there are other tunnels configured, they will be affected as well. You can clear the specific ipsec-esp session by browsing through the options you have in clear session all command from CLI. Once above steps have been carried out, you can try and force the re-negotiations using the commands below : - test vpn ike-sa gateway <name> - test vpn ipsec-sa tunnel <name> If the above steps do not work, then I would suggest building the config from scratch. I would also like to suggest not configuring the lifesize on both the gateways. Thanks
... View more