IPSec+BGP hardening checklist for HA

I put together a concise checklist last week for hardening IPSec+BGP site-to-cloud tunnels while keeping failover clean. It covers IKEv2 AES-256-GCM, PFS group 14+, rekey overlap, DPD 10/3, BGP graceful-restart 120s, dual tunnels per region with ECMP, and notes for AWS TGW and Azure vWAN. Happy to share the doc — anyone running different timers or cipher suites to reduce IKE DoS risk or asymmetric routing pain with NAT-T?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‌⁠‌‍‍‌‌​‌​​⁠​‍‌​​⁠‌‌​​‌‍‌​‌​​‌‌‍‌​​⁠​​​⁠‌‌‌‍‌‍‌‌‌‌‌‌‌‌‌‌​⁠‌⁠‌‌​‍​‍‌⁠⁠‌

On Azure vWAN, we trimmed ‘DPD 10/3’ to 5/2; failover got snappier… Watch false positives under packet loss.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​‌​⁠​⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‌⁠‌⁠‍‌‌‍⁠‌‌‌​‍‌‍⁠‌‌​‌‍‌‌⁠⁠‌​‌​‌⁠‍​​⁠‌‍‌​⁠​‌​⁠​‌‍‌‍​⁠‍‌‌​‍‍‌​‍​​‍​‍‌⁠⁠‌

We stagger SA lifetimes across dual tunnels to avoid rekey overlap; AES-256-GCM’s fine, but prefer group 19 over ‘group 14’.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌‍⁠​‌‍⁠⁠‌⁠‌‌‌‍‌​‌‍​⁠‌‍⁠⁠‌‍⁠‌‌⁠​​‌⁠‌‌‌⁠‌​‌‍‍‌‌‍⁠‍‌‍‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​‌​⁠​⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠​‌​⁠‌‍‌‌‌‌‌​⁠⁠‌‍‍⁠‌‌​‌‌​‍⁠‌​​⁠​⁠‍​​⁠​‌‌​‍​‌‍⁠​​‍⁠‌‌​​⁠‌‍​‍‌⁠‌⁠​‍​‍‌⁠⁠‌