Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

KEY_INVALIDSPI to IKE problem

Hi,

I have Site-to-Site VPN connection between cisco router and series 3000 VPN concnetrator. After some time(it seems after Rekeying Phase 2) no data is passing IPSec tunnel. The tunel is up and the following error is reported on VPN concentrator (clinet ip is 80.253.173.210):

40963 06/12/2007 13:29:43.290 SEV=6 IPSEC/7 RPT=12295

IPSec ESP Tunnel Inb: Could not find security association!

40964 06/12/2007 13:29:43.290 SEV=7 IPSECDBG/15 RPT=5047

Sending KEY_INVALIDSPI to IKE for src 80.253.173.210, spi 0x0e814f53

40965 06/12/2007 13:29:43.300 SEV=6 IPSEC/7 RPT=12296

IPSec ESP Tunnel Inb: Invalid SA or pre-parsing problem!

In the attacment is complete output from the VPN koncentrator and Routers config.

1 REPLY
568
Views
0
Helpful
1
Replies
CreatePlease to create content