Abandoned SAs associated to an IPSEC tunnel
-
I'm wondering if this is SOP or something else. In Status -> IPSec I'm seeing several SAs between two IPs which I have a tunnel configured, but I have only one phase 2 defined. One pair of the SAs actually have traffic indicated while the rest are zero byte.
Site A is running 2.4.4p3 and, based on the logs, requested the recreation of all the SAs on the last REKEY event. Site B is running 2.4.2 and complied.
Is this normal for the protocol?
-
It's normal to see extra copies in there depending on how the negotiation/rekey happened. As long as your traffic is flowing and the tunnel rekeys when needed and keeps going, it's not worth worrying about.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.