Yesterday, I upgraded a remote office XG125 from EAP3 to EAP3-Refresh1 and changed the IP on the local office from DHCP to static with the carrier.
Updated head office XG230 on EAP3 with new remote office static IP, and tunnel connected.
This morning, I updated a second remote office static IP on the head and branch sides of the tunnel, and the link came up.
I then updated the head office to EAP3-Refresh1, and my 5 IPsec tunnels went down.
XG230_WP02_SFOS 18.0.0 EAP3-Refresh1# tail -f /log/strongswan.log
2020-01-22 04:06:59 03[NET] ### drop_ike_sa_init(): rejecting new connections ###
Thanks,
Paul