CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-21
daz306td daz306td is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 22
Rep Power: 0
daz306td has an average reputation (10+)
Default VPN Problem - encryption failure: Unknown SPI: 0x5cf5657c

On a R65 cluster... we had our main internet link die for a for minutes, since then from SecureView Monitor I noticed there was a problem with clusterXL on one of the nodes, I therefore failed over and restarted the node. Once is was back up both nodes (running in HA) became active - which worried me, so I restarted the other node, at that point the operation of clusterXL has looked ok, one node active, one standby.

From our logs a VPN we have has been reporting the following errors..

Quote:
Number: 3106338
Date: 18Apr2008
Time: 16:12:41
Product: VPN-1 Power/UTM
Interface: daemon
Origin: xxxxxxxxxxxxx
Type: Log
Action: Drop
Protocol: ip
Source: xxxxxxxxxxxxx
Rule: 0 - Implied Rules
Information: encryption failure: Unknown SPI: 0x5cf5657c for IPsec packet.
Encryption Scheme: IKE
Subproduct: VPN
VPN Feature: IKE
VPN Peer Gateway: xxxxxxxxxxxxx

Quote:
Number: 3106351
Date: 18Apr2008
Time: 16:13:09
Product: VPN-1 Power/UTM
Interface:
Origin: xxxxxxxxxxxxx
Type: Log
Action: Drop
Protocol: ipv6-crypt
Source: xxxxxxxxxxxxx
Destination: xxxxxxxxxxxxx
Information: encryption fail reason: Packet is dropped because an IPsec SA associated with the SPI on the received IPsec packet could not be found
SmartDefense Profile: No Protection
Obviously I've been required to moved specfic information regarding our nodes.

I tired pushing a new policy, thinking the tunnel could be out of sync, since then the second node on the cluster as flagged errors again in clusterXL

cphaprob list shows...
Quote:
Device Name: Synchronization
Registration number: 0
Timeout: none
Current state: problem
Time since last report: 900.7 sec
and the tunnel still wont come up - any suggestion would be much appericated.

thanks in advance
__________________
Remember to add to someones reputation if they have helped you, by clicking on their scales icon
Reply With Quote
  #2 (permalink)  
Old 2008-04-21
daz306td daz306td is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 22
Rep Power: 0
daz306td has an average reputation (10+)
Default Re: VPN Problem - encryption failure: Unknown SPI: 0x5cf5657c

Oddily the problem has semi-fixed itself. I have rebootted node 01 and the tunnel has come up. However clusterXL is still reporting errors but as this is not a VPN I shall take that elsewhere :D .
__________________
Remember to add to someones reputation if they have helped you, by clicking on their scales icon
Reply With Quote
  #3 (permalink)  
Old 2008-04-21
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: VPN Problem - encryption failure: Unknown SPI: 0x5cf5657c

Sometimes VPN issues have to do with the tunnels not being fully renegotiated, so like keeping phase 1 and trying to only redo phase2. It's also about time and date on both endpoints.
Reply With Quote
  #4 (permalink)  
Old 2008-04-22
daz306td daz306td is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 22
Rep Power: 0
daz306td has an average reputation (10+)
Default Re: VPN Problem - encryption failure: Unknown SPI: 0x5cf5657c

I'm now getting

Quote:
encryption failure: Unknown SPI: 0x5e70c4fa for IPsec packet.
I'm begining to hate R65.
__________________
Remember to add to someones reputation if they have helped you, by clicking on their scales icon
Reply With Quote
  #5 (permalink)  
Old 2008-04-22
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: VPN Problem - encryption failure: Unknown SPI: 0x5cf5657c

Is the cluster in multicast/new mode?

Try pivot/unicast/forwarding mode.

Make sure you have sticky sessions set
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:02.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0