Without relevant logs, it is difficult to troubleshoot. However there could be a timing issue renegotiating the Child SA for Phase 2. According to our public documents (which are present at [1] under references), the Phase 2 lifetime should be 3 hours.
On-premises device must be configured according to our documents [1].
For VPNs using strongSwan, the option is rekeymargin.
For Cisco IOS 11.3+, use the below command:
set crypto ipsec security-association lifetime <seconds>
For JunOS, use the below command:
set security ike proposal lifetime-seconds <seconds>