cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
238
Views
0
Helpful
0
Replies

CSCsl68327 - Packet loss during rekey

aderooy1
Level 1
Level 1

on a Cisco 1941 running 15.1(4)M1 we have a IPSec (static) VPN tunnel that has stopped passing traffic. Encaps and Decaps show 0. Log shows this error:

 

000317: Jan 14 06:04:58.879 EST: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=208.105.126.2, prot=50, spi=0x7980487(127403143), srcaddr=208.125.60.186, input interface=FastEthernet0/0/0

 

Don't support the other end of the tunnel so we are blind to that side. Have cleared isakmp and ipsec sa but did not fix. Interesting traffic is constantly attempting to connect per #send errors 5607, #recv errors 0.

 

Does anyone know what can be done to re-establish the tunnel? 

0 Replies 0