Quantcast
Channel: All EdgeRouter posts
Viewing all articles
Browse latest Browse all 60861

ipsec site-to-site tunnel: received INVALID_IKE_SPI error notify

$
0
0

Getting this error tonight when trying to establish VPN connection.  I won't have access to the remote logs until tomorrow.  Posting in case any one has hit this issue before.

 

ubnt@ubnt:~$ sudo swanctl --log
12[CFG] received stroke: terminate 'peer-sombody.no-ip.org-tunnel-1'
12[CFG] no IKE_SA named 'peer-sombody.no-ip.org-tunnel-1' found
05[CFG] received stroke: initiate 'peer-sombody.no-ip.org-tunnel-1'
01[IKE] initiating Main Mode IKE_SA peer-sombody.no-ip.org-tunnel-1[2] to their.ip.xx
01[ENC] generating ID_PROT request 0 [ SA V V V V ]
01[NET] sending packet: from my.ip.xx[500] to their.ip.xx[500] (156 bytes)
16[NET] received packet: from their.ip.xx[500] to my.ip.xx[500] (128 bytes)
16[ENC] parsed ID_PROT response 0 [ SA V V ]
16[IKE] received NAT-T (RFC 3947) vendor ID
16[IKE] received FRAGMENTATION vendor ID
16[ENC] generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
16[NET] sending packet: from my.ip.xx[500] to their.ip.xx[500] (244 bytes)
15[IKE] sending retransmit 1 of request message ID 0, seq 2
15[NET] sending packet: from my.ip.xx[500] to their.ip.xx[500] (244 bytes)
02[NET] received packet: from their.ip.xx[500] to my.ip.xx[500] (68 bytes)
02[ENC] parsed INFORMATIONAL_V1 request 0 [ N(INVAL_IKE_SPI) ]
02[IKE] received INVALID_IKE_SPI error notify

 

Config is here


Viewing all articles
Browse latest Browse all 60861

Trending Articles