KEY_INVALIDSPI to IKE problem

Unanswered Question
Jun 12th, 2007
User Badges:

Hi,


I have Site-to-Site VPN connection between cisco router and series 3000 VPN concnetrator. After some time(it seems after Rekeying Phase 2) no data is passing IPSec tunnel. The tunel is up and the following error is reported on VPN concentrator (clinet ip is 80.253.173.210):

40963 06/12/2007 13:29:43.290 SEV=6 IPSEC/7 RPT=12295

IPSec ESP Tunnel Inb: Could not find security association!


40964 06/12/2007 13:29:43.290 SEV=7 IPSECDBG/15 RPT=5047

Sending KEY_INVALIDSPI to IKE for src 80.253.173.210, spi 0x0e814f53


40965 06/12/2007 13:29:43.300 SEV=6 IPSEC/7 RPT=12296

IPSec ESP Tunnel Inb: Invalid SA or pre-parsing problem!


In the attacment is complete output from the VPN koncentrator and Routers config.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.

Actions

This Discussion