<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2 firewall and 1 cisco router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344684#M947595</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 1841 cisco router with ports and ip  remote access to locally connected 2 firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those firewalls stablish  2 vpn tunnels. 1 is up an the other one no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This warning is show:&lt;/P&gt;&lt;P&gt;packet has invalid spi for dest address=213.171.249.86, prot=50 spi   srcaddress=217.204.95.134.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why? ther is no crypto configured at router all vpn traffic is configured into the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:44:25 GMT</pubDate>
    <dc:creator>edgar-quintana</dc:creator>
    <dc:date>2020-02-21T11:44:25Z</dc:date>
    <item>
      <title>2 firewall and 1 cisco router</title>
      <link>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344684#M947595</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 1841 cisco router with ports and ip  remote access to locally connected 2 firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those firewalls stablish  2 vpn tunnels. 1 is up an the other one no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This warning is show:&lt;/P&gt;&lt;P&gt;packet has invalid spi for dest address=213.171.249.86, prot=50 spi   srcaddress=217.204.95.134.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why? ther is no crypto configured at router all vpn traffic is configured into the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344684#M947595</guid>
      <dc:creator>edgar-quintana</dc:creator>
      <dc:date>2020-02-21T11:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: 2 firewall and 1 cisco router</title>
      <link>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344685#M947596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this scenario / solution apply to your circumstance:&lt;/P&gt;&lt;P&gt;The %PIX-4-402101: decaps: recd IPSEC packet has invalid spi for destaddr=dest_address, prot=protocol, spi=number error message is received on the PIX Firewall&lt;/P&gt;&lt;P&gt;VERSION 2 &lt;/P&gt;&lt;P&gt;Core issue&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;The received IPsec packet specifies a security parameters index (SPI) that does not exist in the security association database (SADB). This can be a temporary condition due to slight differences in the aging of security associations (SAs) between the IPsec peers or it can be due to the clearing of the local SAs. This condition can also be caused by incorrect packets sent by the IPsec peer.&lt;/P&gt;&lt;P&gt;Note: This can also be an attack.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Resolution&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;The peer may not acknowledge that the local SAs have been cleared. If a new connection is established from the local router, the two peers can then reestablish successfully. Otherwise, if the problem occurs for more than a brief period, either attempt to establish a new connection or contact the peer's administrator.&lt;/P&gt;&lt;P&gt;For more information about PIX Firewall syslog messages, refer to Cisco PIX Firewall System Log Messages, Version 6.3 and Cisco Security Appliance System Log Messages, Version 7.0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Oct 2009 23:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344685#M947596</guid>
      <dc:creator>asafayan</dc:creator>
      <dc:date>2009-10-15T23:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2 firewall and 1 cisco router</title>
      <link>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344686#M947597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I told you, there are 2 firewalls behind the router, both has as default GW routers ip, 192.168.157.254. If I change the firewall's LAN ip from 192.168.157.252 to 192.168.157.251 it works... if router is switched off same error.. changing the ip and solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what's happening?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry about this late response...I was ill&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Oct 2009 20:27:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2-firewall-and-1-cisco-router/m-p/1344686#M947597</guid>
      <dc:creator>edgar-quintana</dc:creator>
      <dc:date>2009-10-31T20:27:48Z</dc:date>
    </item>
  </channel>
</rss>

