Hello , I have a site-to-site ipsec vpn tunnel working between 2 ASA routers. I am trying to understand the behaviour of the tunnel after a connection lost (disconnecting ethernet cable) . Most of the times the tunnel recovers phase 1, negotiates phase 2 and starts working normaly. Some other times i need to ping from one LAN to another to start the tunnel and finally sometimes starts whenever the routers want . Intiator and responder roles vary. In this tunnel there is traffic all the time. Lifetime for rekey phase 1 are 8 hours and for phase 2 is 1 hour, but i have never exceed them making tests.
Is there any mechanism or to make sure that the tunnel is going to get working automatically after a connection lost? Any clue to understand this behaviour?
thank you.