No SPI to identify Phase 2 SA!

Unanswered Question
Dec 1st, 2011
User Badges:

Hi all.

I have a an issue with one particular VPN user. They are using the built in Windows Vista client to connect to my ASA 5510. All other users do not have an issue and i receive the following error at roughly the same time of day when the drop happens. Authentication is done by my AD Server which handles all logins.

<177>%ASA-1-713900: Group = DefaultRAGroup, Username = username, IP = x.x.x.x, construct_ipsec_delete(): No SPI to identify Phase 2 SA!



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Patrick0711 Thu, 12/01/2011 - 08:47
User Badges:
  • Bronze, 100 points or more

Hello Jamie,

Do you have the debug information prior to this message? 


Locayta123 Thu, 12/01/2011 - 08:51
User Badges:

No i don't. That's the only information i have that is displayed.


This Discussion