Hot!IPSec Phase1 Error

Author
ZZDVA0B
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/12/06 14:26:24
  • Status: offline
2020/02/20 12:24:38 (permalink)
0

IPSec Phase1 Error

Hi all,
I'm facing a problem with tunnel IPSEC site-to-site. I receiving the log "INVALID-SPI" and after this Received ESP packet with unknown SPI. Does someone have any idea what it could be?
 
Best Regards
Danilo
#1

7 Replies Related Threads

    ss198939@gmail.com
    Bronze Member
    • Total Posts : 34
    • Scores: 2
    • Reward points: 0
    • Joined: 2016/01/26 05:12:04
    • Status: offline
    Re: IPSec Phase1 Error 2020/02/20 12:26:46 (permalink)
    0
    are you getting second message ? if its main mode ? phase-1 ?
    post edited by ss198939@gmail.com - 2020/02/20 12:39:11
    #2
    ZZDVA0B
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/12/06 14:26:24
    • Status: offline
    Re: IPSec Phase1 Error 2020/02/20 12:34:15 (permalink)
    0
    I have a doubt, because the tunnel towards Remote Gateway is a Dialup user with setting on main mode.
    Sorry, but I don't understood what do You mean with "are you getting third message".
     
    Thanks in advance
    #3
    ss198939@gmail.com
    Bronze Member
    • Total Posts : 34
    • Scores: 2
    • Reward points: 0
    • Joined: 2016/01/26 05:12:04
    • Status: offline
    Re: IPSec Phase1 Error 2020/02/20 12:38:44 (permalink)
    0
    sorry


    I wanted to mention second message


    take packet capture and see how many messages you are getting.

    main mode have 6 message for phase 1


    for aggressive mode its 4 message


    if you are not getting second message then there is some mismatch in parameters
    #4
    ede_pfau
    Expert Member
    • Total Posts : 6241
    • Scores: 522
    • Reward points: 0
    • Joined: 2004/03/09 01:20:18
    • Location: Heidelberg, Germany
    • Status: offline
    Re: IPSec Phase1 Error 2020/02/21 03:54:26 (permalink)
    0
    Per se, these messages do not suggest that you have a problem. It's just that your FGT is listening for IPsec (AH, ESP) and incoming traffic is not related to any VPN you have created/used.
    Unless I'm totally off, and you can clarify the situation you have.

    Ede

    " Kernel panic: Aiee, killing interrupt handler!"
    #5
    ad
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/12/10 19:26:30
    • Status: offline
    Re: IPSec Phase1 Error 2020/02/24 17:09:21 (permalink)
    0
    From Wikipedia;
    "The Security Parameter Index (SPI) is an identification tag added to the header while using IPsec for tunneling the IP traffic. This tag helps the kernel discern between two traffic streams where different encryption rules and algorithms may be in use."
     
    So it looks like either;
    1. the tunnel was setup but it has expired on your end, or
    2. its a stray packet for something else
     
    If #1, then check that the timer and data volume rekeying parameters are the same on both ends of the tunnel
    If #2, do the endpoint IPs match?
     
    My first guess would be that you have a shorter timer on your IPSec SAs than the remote end has, but usually tunnels fail to setup when parameters dont match. I have no experience with Forti IPSec...
    #6
    sw2090
    Platinum Member
    • Total Posts : 551
    • Scores: 39
    • Reward points: 0
    • Joined: 2017/06/14 01:27:25
    • Location: Regensburg
    • Status: offline
    Re: IPSec Phase1 Error 2020/02/25 08:03:13 (permalink)
    0
    I'd suggest looking into debug log on cli:
     
     diag debug ena
     diag debug application ike -1
     
    (diag debug application ike 0 disables it again)
     
    while this runs try to establish the vpn.
    It is ofthe neccessary to log at logs on both ends to find the problem.
     
    #7
    ZZDVA0B
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/12/06 14:26:24
    • Status: offline
    Re: IPSec Phase1 Error 2020/03/23 01:59:54 (permalink)
    0
    Hello,
    I solved the problem with a simply reboot of the Appliance.
    Thanks a lot.
    BRs
    Danilo
    #8
    Jump to:
    © 2020 APG vNext Commercial Version 5.5