No SPI to identify Phase 2 SA!

Unanswered Question
Dec 1st, 2011

Hi all.

I have a an issue with one particular VPN user. They are using the built in Windows Vista client to connect to my ASA 5510. All other users do not have an issue and i receive the following error at roughly the same time of day when the drop happens. Authentication is done by my AD Server which handles all logins.

<177>%ASA-1-713900: Group = DefaultRAGroup, Username = username, IP = x.x.x.x, construct_ipsec_delete(): No SPI to identify Phase 2 SA!



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Patrick0711 Thu, 12/01/2011 - 08:47

Hello Jamie,

Do you have the debug information prior to this message? 


Locayta123 Thu, 12/01/2011 - 08:51

No i don't. That's the only information i have that is displayed.


This Discussion