×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

The %PIX-4-402101: decaps: recd IPSEC packet has invalid spi for destaddr=dest_address, prot=protocol, spi=number error message is received on the PIX Firewall

Document

Wed, 07/22/2009 - 19:57
Jun 22nd, 2009
User Badges:
  • Gold, 750 points or more

Core issue

The received IPsec packet specifies a security parameters index (SPI) that does not exist in the security association database (SADB). This can be a temporary condition due to slight differences in the aging of security associations (SAs) between the IPsec peers or it can be due to the clearing of the local SAs. This condition can also be caused by incorrect packets sent by the IPsec peer.

Note: This can also be an attack.


Resolution


The peer may not acknowledge that the local SAs have been cleared. If a new connection is established from the local router, the two peers can then reestablish successfully. Otherwise, if the problem occurs for more than a brief period, either attempt to establish a new connection or contact the peer's administrator.

For more information about PIX Firewall syslog messages, refer to Cisco PIX Firewall System Log Messages, Version 6.3 and Cisco Security Appliance System Log Messages, Version 7.0.

Loading.

Actions

This Document

Related Content