I have found increased stability with an RV042<->RV042 Gateway-to-gateway VPN connection by setting the Phase 2 lifetime to 900 seconds (15 minutes). A tip-off in another thread re: clock drift led me to experiment with this. Higher values and the tunnel seems to go stale; neither DPD nor Keep-alive do their jobs at keeping the tunnel up. Both RV042's show the tunnel as connected, but actual connections between sites fail. What is the downside to a relatively short Phase 2 lifetime? FWIW, I am going with a Phase 1 lifetime of 28800 (8 hrs).