Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

received IKE message with invalid SPI (C8A9D1D2) from other side

check in the blogs and forums and all discussions end in "support engineer solved this" but there is no explanation on how.

we have two XG F/W across a WAN working site-2-site VPN flawlessly for about 4 days, out of the blue one end receives the "received IKE message with invalid SPI (C8A9D1D2) from other side" and the VPN goes down.

One end shows VPN link UP/DOWN the other siteshows UP/UP



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    Could you please share the screenshots of the configured IPsec policies from both firewalls? 

    Also, ensure that DPD(Dead Peer Detection) isn't set to Re-initiate on the IPsec connection, configured as "Respond only" gateway. 

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    Could you please share the screenshots of the configured IPsec policies from both firewalls? 

    Also, ensure that DPD(Dead Peer Detection) isn't set to Re-initiate on the IPsec connection, configured as "Respond only" gateway. 

    Thanks,

Children