So I have just recently deployed a meraki MX80 at our corporate office and part of the migration would be to bring our remote Juniper SRX's to connect to the meraki instead of our Juniper SRX200 we currently have. However I have spent hours and a few more hours with Meraki trying to get it to be stable.
The problem is the phase 2, it connects but for some reason it keeps rekeying about every 140 seconds. I have it set to 28800 and unlimited on the juniper so I know it's not the juniper box requesting the rekey. Anyone else have this going and working? The problem is during the rekey all data transmissions stop to the far end of the tunnel.
Apr 26 15:06:06 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=574020562(0x2236dbd2)
Apr 26 15:06:06 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=34119445(0x2089f15)
Apr 26 15:04:16 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=1744746987(0x67feb9eb)
Apr 26 15:04:16 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=170298032(0xa268ab0)
Apr 26 15:02:27 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=222282702(0xd3fc3ce)
Apr 26 15:02:27 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=73284145(0x45e3a31)
Apr 26 15:02:26 VPN msg: initiate new phase 2 negotiation: WAN IP CORP[500]<=WAN IP REMOTE[500]
Apr 26 15:00:36 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=997706878(0x3b77cc7e)
Apr 26 15:00:36 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=89206639(0x5512f6f)
Apr 26 15:00:36 VPN msg: initiate new phase 2 negotiation: WAN IP CORP[500]<=WAN IP REMOTE[500]
Apr 26 14:58:47 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=541864844(0x204c338c)
Apr 26 14:58:47 VPN msg: IPsec-SA established: ESP/Tunnel WAN IP CORP[500]-WAN IP REMOTE[500] spi=165725526(0x9e0c556)
Apr 26 14:58:47 VPN msg: initiate new phase 2 negotiation: WAN IP CORP[500]<=WAN IP REMOTE[500]