Hacker News new | ask | show | jobs
by fulafel 2134 days ago
IPsec is pretty light.
1 comments

Doesn't feel light to setup if you're trying to get a tunnel working between different providers. We had a strange dead peer issue between Fortigate and Mikrotik and could never figure it out as it happened so rarely. All phase 1 and phase 2 settings were identical. I can imagine that happens elsewhere too.
Try enabling Dead Peer Detection (DPD).
Both sides had that on from the beginning.