It turned out that when I added an extra traffic selector in phase II, wether the other side (out of our control) did not configure correctly or there is an interop issue between Junos and ASA, the other side sent us a notification which caused IKE phase I SA to be deleted. Interestingly the IPsec SA for existing traffic-selector is still active, not sure whether this is expected behavior.
↧