I have setup a central DSR-1000N that connects via IPsec to three remote DSR-250N and two remote DSR-1000N in a star structure.
Initially everything works fine. But after a few weeks two of the DSR-250N started getting troubles to reconnect to the DSR-1000N. The status on de 1000 is 'IPsec SA Not Established' but on the remote site (DSR-250) the status is 'IPsec SA Established', but that is evidently wrong, because I cannot ping from the central location to the LAN of the remote site.
After rebooting the connection comes up, but fails after an hour or so. After rebooting the remote 250, the connection is established again, but fails after an hour or so.
The 250's are all configured the same. Firmware for 1000n's: 1.08B51_WW and on the 250n's: 1.05B73_WW. I've enabled dead pear detection and set NAT keep alive to 20
The other 3 sites (DSR-250 / 1000N) are working fine.
Who has some good ideas to look at?