IKE protocol notification message received: INVALID-SPI (11).

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IKE protocol notification message received: INVALID-SPI (11).

L2 Linker

Dears,

 

I have a site to site VPN between PAN 7.1.6 and Cisco ASA 8.2.5, I'm receiving a lot of Invalid SPI error. I tried to reset the VPN many times and still having the same issue. This issue by the way is casusing a lot of packet dropes in the VPN

 

 

'IKE protocol notification message received: INVALID-SPI (11).'

 

Did any one faced a similer issue or have an idea on how to mitigate such issue ?

17 REPLIES 17

L6 Presenter

Hi,

 

Please post an output of the below command:

 

> tail lines 50 mp-log ikemgr.log

The output of the command:

 

2017-05-11 23:12:11 [INFO]: SADB_ADD ul_proto=255 src=196.3.15.6[500] dst=37.200.227.2[500] satype=ESP samode=tunl spi=0x82DA0798 authtype=SHA1 enctype=AES256 enclen=32 lifetime soft time=23699 bytes=4718592000 hard time=28800 bytes=4718592000
2017-05-11 23:12:11 [INFO]: IPsec-SA established: ESP/Tunnel 37.200.227.2[500]->196.3.15.6[500] spi=2404262458(0x8f4e223a)
2017-05-11 23:12:11 [PROTO_NOTIFY]: ====> IPSEC KEY INSTALLATION SUCCEEDED <====
====> Installed SA: 196.3.15.6[500]-37.200.227.2[500] SPI:0x8F4E223A/0x82DA0798 lifetime 28800 Sec lifesize 4608000 KB <====
2017-05-11 23:12:11 [INFO]: keymirror add start ++++++++++++++++
2017-05-11 23:12:11 [INFO]: keymirror add for gw 0x62, tn 165, selfSPI 8F4E223A, retcode 0.
2017-05-11 23:12:12 [INFO]: keymirror del start ----------------
2017-05-11 23:12:12 [INFO]: keymirror del for gw 62, tn 165, selfSPI DE59D8F2, retcode 0.
2017-05-11 23:12:12 [PROTO_NOTIFY]: ====> IPSEC KEY DELETED <====
====> Deleted SA: 196.3.15.6[500]-37.200.227.2[500] SPI:0xDE59D8F2/0x895B2115 <====
2017-05-11 23:12:12 [INFO]: SADB_DELETE ul_proto=0 src=196.3.15.6[500] dst=37.200.227.2[500] satype=ESP spi=0xDE59D8F2
2017-05-11 23:12:12 [INFO]: received PFKEY_DELETE seq=0 satype=ESP spi=0xDE59D8F2
2017-05-11 23:12:13 [PROTO_NOTIFY]: ====> PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) <====
====> Initiated SA: 196.3.15.6[500]-37.200.227.2[500] message id:0x53707D24 <====
2017-05-11 23:12:13 [PROTO_NOTIFY]: ====> PHASE-2 NEGOTIATION SUCCEEDED AS RESPONDER, (QUICK MODE) <====
====> Established SA: 196.3.15.6[500]-37.200.227.2[500] message id:0x53707D24, SPI:0x88E48F13/0x45A3A41B <====
2017-05-11 23:12:13 [INFO]: SADB_UPDATE ul_proto=255 src=37.200.227.2[500] dst=196.3.15.6[500] satype=ESP samode=tunl spi=0x88E48F13 authtype=SHA1 enctype=AES256 enclen=32 lifetime soft time=28800 bytes=4718592000 hard time=28800 bytes=4718592000
2017-05-11 23:12:13 [INFO]: SADB_ADD ul_proto=255 src=196.3.15.6[500] dst=37.200.227.2[500] satype=ESP samode=tunl spi=0x45A3A41B authtype=SHA1 enctype=AES256 enclen=32 lifetime soft time=24717 bytes=4718592000 hard time=28800 bytes=4718592000
2017-05-11 23:12:13 [INFO]: IPsec-SA established: ESP/Tunnel 37.200.227.2[500]->196.3.15.6[500] spi=2296680211(0x88e48f13)
2017-05-11 23:12:13 [PROTO_NOTIFY]: ====> IPSEC KEY INSTALLATION SUCCEEDED <====
====> Installed SA: 196.3.15.6[500]-37.200.227.2[500] SPI:0x88E48F13/0x45A3A41B lifetime 28800 Sec lifesize 4608000 KB <====
2017-05-11 23:12:13 [INFO]: keymirror add start ++++++++++++++++
2017-05-11 23:12:13 [INFO]: keymirror add for gw 0x62, tn 238, selfSPI 88E48F13, retcode 0.
2017-05-11 23:12:13 [INFO]: keymirror del start ----------------
2017-05-11 23:12:13 [INFO]: keymirror del for gw 62, tn 238, selfSPI BED9420E, retcode 0.
2017-05-11 23:12:13 [PROTO_NOTIFY]: ====> IPSEC KEY DELETED <====
====> Deleted SA: 196.3.15.6[500]-37.200.227.2[500] SPI:0xBED9420E/0x6676265D <====
2017-05-11 23:12:13 [INFO]: SADB_DELETE ul_proto=0 src=196.3.15.6[500] dst=37.200.227.2[500] satype=ESP spi=0xBED9420E
2017-05-11 23:12:13 [INFO]: received PFKEY_DELETE seq=0 satype=ESP spi=0xBED9420E
2017-05-11 23:12:15 [PROTO_NOTIFY]: ====> PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) <====
====> Initiated SA: 196.3.15.6[500]-37.200.227.2[500] message id:0x53573711 <====
2017-05-11 23:12:15 [PROTO_NOTIFY]: ====> PHASE-2 NEGOTIATION SUCCEEDED AS RESPONDER, (QUICK MODE) <====
====> Established SA: 196.3.15.6[500]-37.200.227.2[500] message id:0x53573711, SPI:0xAB25A184/0x4B96A1DB <====
2017-05-11 23:12:15 [INFO]: SADB_UPDATE ul_proto=255 src=37.200.227.2[500] dst=196.3.15.6[500] satype=ESP samode=tunl spi=0xAB25A184 authtype=SHA1 enctype=AES256 enclen=32 lifetime soft time=28800 bytes=4718592000 hard time=28800 bytes=4718592000
2017-05-11 23:12:15 [INFO]: SADB_ADD ul_proto=255 src=196.3.15.6[500] dst=37.200.227.2[500] satype=ESP samode=tunl spi=0x4B96A1DB authtype=SHA1 enctype=AES256 enclen=32 lifetime soft time=24531 bytes=4718592000 hard time=28800 bytes=4718592000
2017-05-11 23:12:15 [INFO]: IPsec-SA established: ESP/Tunnel 37.200.227.2[500]->196.3.15.6[500] spi=2871370116(0xab25a184)
2017-05-11 23:12:15 [PROTO_NOTIFY]: ====> IPSEC KEY INSTALLATION SUCCEEDED <====
====> Installed SA: 196.3.15.6[500]-37.200.227.2[500] SPI:0xAB25A184/0x4B96A1DB lifetime 28800 Sec lifesize 4608000 KB <====
2017-05-11 23:12:15 [INFO]: keymirror add start ++++++++++++++++
2017-05-11 23:12:15 [INFO]: keymirror add for gw 0x62, tn 239, selfSPI AB25A184, retcode 0.
2017-05-11 23:12:16 [INFO]: keymirror del start ----------------
2017-05-11 23:12:16 [INFO]: keymirror del for gw 62, tn 239, selfSPI D27B0ECA, retcode 0.
2017-05-11 23:12:16 [PROTO_NOTIFY]: ====> IPSEC KEY DELETED <====
====> Deleted SA: 196.3.15.6[500]-37.200.227.2[500] SPI:0xD27B0ECA/0xEF3B3C45 <====
2017-05-11 23:12:16 [INFO]: SADB_DELETE ul_proto=0 src=196.3.15.6[500] dst=37.200.227.2[500] satype=ESP spi=0xD27B0ECA
2017-05-11 23:12:16 [INFO]: received PFKEY_DELETE seq=0 satype=ESP spi=0xD27B0ECA
2017-05-11 23:12:18 [PROTO_NOTIFY]: notification message 11:INVALID-SPI, doi=1 proto_id=3 spi=27f42f2f(size=4).
2017-05-11 23:12:24 [PROTO_NOTIFY]: notification message 11:INVALID-SPI, doi=1 proto_id=3 spi=27f42f2f(size=4).
2017-05-11 23:12:36 [PROTO_NOTIFY]: notification message 11:INVALID-SPI, doi=1 proto_id=3 spi=728a83a3(size=4).
2017-05-11 23:12:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=ab1b78c39120cd9e 7be127d67dcd5923 (size=16).

by the way i'm facing VPN disconnections with all IPSEC with ASA on the other side.

How are your proxy id's settings looks like? Are they matching? DPD setting  (timers) should also match. Can you please confirm this

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!