This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site ipsec

Main XG has bee updated for about a week.  2 remote site Xg's both were on SFOS 17.0.3 MR-3.  I just updated one of them to SFOS 17.0.6 MR-6.  After the update to 1706 it will not connect its vpn anymore.

I see this in the log:  received IKE message with invalid SPI (646753DB) from other side  The other one that is on 1703 is still connected to the ipsec vpn.  



This thread was automatically locked due to age.
Parents Reply
  • Both of these are fully upgraded.

    I tried this before but I did it again from scratch.  Copied the ikev2 to a new policy on each xg and edited it just as you said, only 1 algorithm per phase.  Remote site is set to 0 Key tries - Head Office set to 3.  DPD the remote is re-initiate - Head office is disconnect.  Everything else matches in the ipsec policy.  

    Now when i activate the connection on each end i get this in the log:  creating local authentication data failed

Children