In VMware NSX, an IPsec VPN tunnel may disconnect or transition to a 'Down' state when there is no active user data traffic. This behavior typically occurs when the remote peer device or intermediate network infrastructure enforces idle timers that tear down the Security Association (SA) in the absence of traffic.
IPsec sessions are often configured with idle timers on the remote peer device. If no data plane traffic is detected within the specified interval, the remote peer initiates a deletion of the Security Association (SA) to conserve resources. This is an expected behavior of the IPsec protocol implementation on many third-party gateway devices when keepalives or data packets are not present.
To maintain an active IPsec VPN tunnel and monitor its health during periods of inactivity, implement one of the following workarounds: