I did eventually figure this out. First I had some mild success by enabling NAT-T but I'd still have the regular drops. Then while working with a completely unrelated tunnel on a different device I realized my ISP router had ESP ALG inspection enabled. As soon as I disabled that everything was rock solid.
↧