This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site ipsec

Main XG has bee updated for about a week.  2 remote site Xg's both were on SFOS 17.0.3 MR-3.  I just updated one of them to SFOS 17.0.6 MR-6.  After the update to 1706 it will not connect its vpn anymore.

I see this in the log:  received IKE message with invalid SPI (646753DB) from other side  The other one that is on 1703 is still connected to the ipsec vpn.  



This thread was automatically locked due to age.
Parents
  • Hey  

    I would advise to schedule downtime and upgrade the rest of your XG firewall appliances to SFOS 17.0.6 MR-6 for consistency among the tunnels. Please let me know if you still experience issues after performing this. 

    Regards,

    FloSupport | Community Support Engineer

  • Im afraid to upgrade the other one (only have 3) since i can't get this one to make a tunnel at all.

    I have made a new copy of the defaultHeadOffice and defaultremoteoffice ipsec profiles edited the weaker security in them make sure they matched on both the Main XG and the remote XG.  Assigned each one to the tunnel.  Still no go. Even rebooted both XG units and nothing. 

     

     

Reply
  • Im afraid to upgrade the other one (only have 3) since i can't get this one to make a tunnel at all.

    I have made a new copy of the defaultHeadOffice and defaultremoteoffice ipsec profiles edited the weaker security in them make sure they matched on both the Main XG and the remote XG.  Assigned each one to the tunnel.  Still no go. Even rebooted both XG units and nothing. 

     

     

Children