received IKE message with invalid SPI from other side

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-23-2021 12:36 PM
there are two Tunnels in NSX edge
1- one between NSX to branch ( Sophos FW ) and it is working fine no issue
2- another one in the same NSX and other sites ( Sophos ) also and we have some times ( 3-4) disconnection for 30 sec
and I have attached the Log when disconnection has happened, (received IKE message with invalid SPI from another side)
is there anyone who has a good solution for this
- Labels:
-
IPSEC
-
Other VPN Topics
-
VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-23-2021 12:52 PM
what kind of cisco device is this, what is the code running, can you share more information or config to understand the problem correctly.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-23-2021 01:01 PM
no cisco Devices it is between NSX-Edge and sphose and the configuration is correct because we faced this issue just some times for 30 sec
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-23-2021 01:07 PM
Not sure if this is not related to any cisco devices, you posting the wrong forum or community (hope if i am not wrong here ?)
here is some reference link for the respected diagnosis :
https://community.sophos.com/xg-firewall/f/discussions/118581/ike-message-with-invalid-spi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-23-2021 04:09 PM
can I see the Nexus Config ?
