Hi ,
Based on my understanding, IKEv2 connections to Windows RRAS servers sporadically fail. The RRAS servers are behind a load balancer and the load balancer NAT the IPsec connections. Is that right? Please feel free to let me know, if my understanding is wrong.
Please check the following article to see if it helps:
Always On VPN IKEv2 Load Balancing and NAT
Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
In your case, we might need to analyze IKE Debug logging to see if there is any error like Max number of established MM SAs to peer exceeded or ERROR_IPSEC_IKE_MM_LIMIT. However, please understand, analysis of traffic is beyond our forum support level. If you want to find root cause, I would suggest you open a case with Micorosoft.
If you can find any error message related to MM SAs, then you can modify IkeNumEstablishedForInitialQuery value in registry and see if the problem is solved.
Best Regards,
Candy
--------------------------------------------------------------
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.