This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site ipsec

Main XG has bee updated for about a week.  2 remote site Xg's both were on SFOS 17.0.3 MR-3.  I just updated one of them to SFOS 17.0.6 MR-6.  After the update to 1706 it will not connect its vpn anymore.

I see this in the log:  received IKE message with invalid SPI (646753DB) from other side  The other one that is on 1703 is still connected to the ipsec vpn.  



This thread was automatically locked due to age.
Parents Reply
  • I tried to make a copy and also delete the connection at both XG's.  Even tried using new keys.  They will not connect anymore.  I also tried to roll the remote XG back to 1703 and it will not connect like that either.  

     

    What logs should I be looking at?  In the System Log I see this:  peer did not respond to initial message 31 followed by parsing IKE message from 123.123.123.123[500] failed

Children