05-30-2022 06:38 PM
Hello Experts, @Marvin Rhoads @balaji.bandi @Rob Ingram
I have an IPSec tunnel setup with Cisco ASA and Sonicwall NSA. The tunnel works fine with some packet drops and it happens on Sonicwall. I worked with SonicWALL Support and found that ASA sent some ESP headers with invalid SPI, resulting in a drop.
Please see the attached screenshots.
What is SPI ? in ESP Headers.
Also, what should I do on ASA to find that exact root cause?
I can verify that ISPs have no issues on both sides and Firewalls got other tunnels working fine showing the same kind of Hashing/encryption algorithms
Thanks,
Lovejit Singh
05-30-2022 10:58 PM - edited 05-30-2022 10:58 PM
below are some documents available t-shoot very well describe the issue.
hope it will help you..
below is the Article from the Sonicwall for workaround for this issue.
Thanks,
Jitendra
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide