Has this tunnel worked before? is this a new setup? did the tunnel go down and is not coming up or something? invalid SPI would mean that the tunnel is active but out of sync what are the vpn endpoints?
The VPN works before you migrate one of the firewall. Previously, the two firewalls SPI matched. When you migrate one of the firewall, the new firewall SPI start to zero while the other end firewall SPI could already reached 10 digits. You need to reset the SPI of the other firewall.
I experience this in Routers where I found it later as an IOS bug. Haven't experience this in PIX/ASA so far but I know that it happens to some and most of the events that triggers it are;
- One end Router/Firewall replaced/migrated
- One end Router/Firewall OS upgrade and rebooted
- One end Router/Firewall was down for a long period of time
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...