cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
703
Views
0
Helpful
1
Replies

KEY_INVALIDSPI to IKE problem

Branimir Turk
Level 1
Level 1

Hi,

I have Site-to-Site VPN connection between cisco router and series 3000 VPN concnetrator. After some time(it seems after Rekeying Phase 2) no data is passing IPSec tunnel. The tunel is up and the following error is reported on VPN concentrator (clinet ip is 80.253.173.210):

40963 06/12/2007 13:29:43.290 SEV=6 IPSEC/7 RPT=12295

IPSec ESP Tunnel Inb: Could not find security association!

40964 06/12/2007 13:29:43.290 SEV=7 IPSECDBG/15 RPT=5047

Sending KEY_INVALIDSPI to IKE for src 80.253.173.210, spi 0x0e814f53

40965 06/12/2007 13:29:43.300 SEV=6 IPSEC/7 RPT=12296

IPSec ESP Tunnel Inb: Invalid SA or pre-parsing problem!

In the attacment is complete output from the VPN koncentrator and Routers config.

1 Reply 1
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: