cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
604
Views
0
Helpful
1
Replies

Problen with IPSEC ikev2 - CRYPTO-4-RECVD_PKT_INV_SPI

Hi guys,

In these days i saw in my cisco that it shows me a message with this error:

%CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr

This ipsec configuration was working without any problem but for a few days it does not allow to establish the ipsec tunnel through a certificate (RSA authentication)

I set this configuration crypto isakmp invalid-spi-recovery but i have the same result

Can somebody help me ?

 

1 Reply 1

I am having the same issue with DMVPN and IKEv2 IPSec tunnel protection. The strange thing is I have 2 DMVPN hubs and this is only happening on the secondary hub.
%CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=....
The DMVPN tunnels on hub2 are never older than 2 hours but last many weeks on hub1. All crypto config is the same and there should not be any difference in configuration.
When I clear crypto ikev2 sa remote (hub2 public IP) on the spoke the DMVPN towards hub2 goes up.

Any ideas what is going on ?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: