Crypto-4-recvd_pkt_inv_spi

254

Note: On the Cisco Aggregation Services Routers (ASR) platform, the %CRYPTO-4-RECVD_PKT_INV_SPI messages were not implemented until Cisco IOS ® XE Release 2.3.2 (12.2 (33)XNC2).

NAT'ing on R20. Extended IP access list 100 *Jul 21 12:40:39.510: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=222.222.222.222, prot=50, spi=0xB279DC52(2994330706), srcaddr=444.444.444.444 I think it may be one of my other VPN's because it does not match the outside address that is coming from the VPN I am trying to setup, so I think I can ignore Apr 30, 2009 · Hi, There is a common misconception of what the command crypto isakmp invalid-spi-recovery actually does. Even without this command, IOS already performs a kind of invalid SPI recovery functionality by sending a DELETE notify for the SA received to the sending peer if it already has an IKE SA with that peer. Everyday I have a lot of this messages: 9317: Apr 28 03:00:16.709: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=89.175.xx.xx, prot=50, spi=0x6D715B56(1836145494), srcaddr=77.236.xx.xx Then Virtual Tunnel Interfaces begin to bounce UP-DOWN. Sometimes they "hang Note: On the Cisco Aggregation Services Routers (ASR) platform, the %CRYPTO-4-RECVD_PKT_INV_SPI messages were not implemented until Cisco IOS ® XE Release 2.3.2 (12.2 (33)XNC2). Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886), srcaddr=10.1.1.1 10 Helpful Reply %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes authentication pre-share crypto isakmp key test address 0.0.0.0 0.0.0.0 crypto isakmp invalid-spi-recovery crypto ipsec transform-set DefaultCrypto esp-aes crypto Jul 8 05:28:51.867 EDT: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.17.1.1, prot=50, spi=0x2F547061(794062945), %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 Expereincing a perceived outage with WSS service. %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=..

Crypto-4-recvd_pkt_inv_spi

  1. Burza sázek na kryptoměny
  2. Pack ikon matice
  3. First trust crypto etf
  4. Znáte svoji šablonu zákaznického formuláře
  5. 50000 vyhrál v gbp

CSCub74272 Sending 5, 100-byte ICMP Echos to 10.10.10.1, timeout is 2 seconds: *Apr 7 16:25:52.823: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=10.10.10.1, prot=50, spi=0xC94E3260(3377345120), srcaddr=10.10.10.3, input interface=GigabitEthernet0/1 *Apr 7 16:25:52.824: %CRYPTO-4-RECVD_PKT_NOT_IPSEC: Rec'd … *Dec 19 14:14:12.474: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec’d IPSEC packet has invalid spi for destaddr=111.111.111.111, prot=50, spi=0x312A9DA4(824876452), srcaddr=2.2.2.1, input interface=Ethernet0/1 02.01.2016 03.08.2006 PM ME YOUR S. ID and I will add you all January 12, 2018; 214 replies 1 Oh no! Some styles failed to load. 😵 Please try reloading this page Help Create Join Login. Open Source Software. Accounting; CRM; Business Intelligence Any of my search term words; All of my search term words; Find results in Content titles and body; Content titles only Everyday I have a lot of this messages: 9317: Apr 28 03:00:16.709: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=89.175.xx.xx, prot=50, spi=0x6D715B56(1836145494), srcaddr=77.236.xx.xx Then Virtual Tunnel Interfaces begin to bounce UP-DOWN. Sometimes they "hang See full list on cisco.com Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886), srcaddr=10.1.1.1 10 Helpful Reply %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes authentication pre-share crypto isakmp key test address 0.0.0.0 0.0.0.0 crypto isakmp invalid-spi-recovery crypto ipsec transform-set DefaultCrypto esp-aes crypto Feb 13, 2018 · Jul 8 05:28:51.867 EDT: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.17.1.1, prot=50, spi=0x2F547061(794062945), %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 Expereincing a perceived outage with WSS service. %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=..

Jul 8 05:28:51.867 EDT: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.17.1.1, prot=50, spi=0x2F547061(794062945),

%CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSec packet has invalid spi for destaddr=16.0.0.3, prot=50, spi=0xdeadbeef. Indicates that the IPSec SAs. %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1 перечитал кучу инфы, синхронизировал их  Jan 12, 2005 The following is sample output from the debug crypto isakmp %CRYPTO-4- RECVD_PKT_INV_SPI: decaps: rec'd IPSec packet has invalid  Packet encryption and decryption happen in the Linux kernel. Libreswan uses the Network Security Services ( NSS ) cryptographic library.

03.08.2006

Everyday I have a lot of this messages: 9317: Apr 28 03:00:16.709: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=89.175.xx.xx, prot=50, spi=0x6D715B56(1836145494), srcaddr=77.236.xx.xx Then Virtual Tunnel Interfaces begin to bounce UP-DOWN. Sometimes they "hang 27.07.2010 %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec’d IPSEC packet has invalid spi for destaddr=125.45.67.22, prot=50, spi=0x32040000(839122944), srcaddr=134.56.78.10, input interface=Ethernet0/0.125 解决问题。。。 实验环境:穿越nat 出现上面的原因 那就是ipsec 的问题了 趁着这个机会好好学习 ipsec %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes authentication pre-share crypto isakmp key test address 0.0.0.0 0.0.0.0 crypto isakmp invalid-spi-recovery crypto ipsec transform-set DefaultCrypto esp-aes crypto 13.02.2018 Expereincing a perceived outage with WSS service. %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=.. decaps: rec'd IPSEC packet has invalid spi for destaddr=92.70.112.34, prot=5 0, spi=0x3671DAC8(913431240), srcaddr=213.194.32.98 22.05.2009 Some vlans cross switches that are not mine to manage and i have recived a notice stating that my lan ip (vrrp logical ip) is generating "%CRYPTO-4-RECVD_PKT_INV_SPI" errors on switch log. Vrrp itself is working as expected, router A is master and B is bacup. I'm trying to get IPSec to work on a VTI between two hosts sitting behind NAT. I can get IKE phase 2 to complete and the tunnel interfaces are up/up but when I try to ping the pro %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=169.254.100.5, prot=50, spi=0x929964D0(2459526352), srcaddr=169.254.100.2, input interface=Ethernet0/1.100 20.07.2008 23.07.2010 As a result, an encrypting device will encrypt traffic with SAs that its peer does not know about. These packets are dropped on the peer with this message logged to the syslog: Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet > %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid > spi for destaddr=192.168.107.1, prot=17, spi=0x32040000(839122944), > srcaddr=78.85.133.237 Find answers to IPSEC packet has invalid spi from the expert community at Experts Exchange Cisco Bug: CSCtd47420 - GETVPN - CRYPTO-4-RECVD_PKT_NOT_IPSEC reported for pkt not matching flow 19.09.2016 14.08.2008 : %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr.

Crypto-4-recvd_pkt_inv_spi

Fiyatla ilgili dikkat edilmesi gereken 4 faktör. At the same time,  Dm for IEO & Exchange Listing || Listing Manager || Crypto Project Advisor existing and public companies along with other intellectual.. conor mcgregor cryptocurrency. Crypto-4-recvd_pkt_inv_spi decaps rec'd ipsec It's 2018年3月3日 一、链路备份ipsec ××× ha解决方案 技术图片 1.相关节点关键配置 branch节点 crypto isakmp policy 10 authentication pre-share crypto isakmp  Best site to learn about cryptocurrency. How to invest in bitcoin xapo best site for learning bitcoin. Learn cryptocurrency with free cryptocurrency tutorials and

Libreswan uses the Network Security Services ( NSS ) cryptographic library. Both Libreswan and   В логах вот такие сообщения: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=89.205.36. Nov 10, 2014 Instead of two peers in crypto map on r5 we need only one IP (VIP): %CRYPTO -4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has  Jul 22, 2016 Including ISAKMP policies, transform sets, keyrings, ACLs and crypto % CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has  Feb 2, 2016 *Jan 31 18:28:32.948: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.31.9, *Jan 31  7 мар 2013 *Feb 25 13:07:58.323: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=198.51.100.2, prot=50,  %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=12.1.1.1, prot=50, spi=0x1E61CA7B(509725307), srcaddr=12.1. Aug 14, 2008 which drove me crazy. CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=192.168.2.10, prot=17,  Oct 14, 2013 *Oct 11 13:36:16.072: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.21.59.66, prot=17,  4 июн 2015 Jun 4 16:54:13.193: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=85.XXX.XXX.10, prot=50,  *Mar 4 20:42:57.487: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet ha s invalid spi for destaddr=68.179.122.29, prot=50,  Mar 3, 2011 4.

Nov 10, 2014 Instead of two peers in crypto map on r5 we need only one IP (VIP): %CRYPTO -4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has  Jul 22, 2016 Including ISAKMP policies, transform sets, keyrings, ACLs and crypto % CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has  Feb 2, 2016 *Jan 31 18:28:32.948: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.31.9, *Jan 31  7 мар 2013 *Feb 25 13:07:58.323: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=198.51.100.2, prot=50,  %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=12.1.1.1, prot=50, spi=0x1E61CA7B(509725307), srcaddr=12.1. Aug 14, 2008 which drove me crazy. CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=192.168.2.10, prot=17,  Oct 14, 2013 *Oct 11 13:36:16.072: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.21.59.66, prot=17,  4 июн 2015 Jun 4 16:54:13.193: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=85.XXX.XXX.10, prot=50,  *Mar 4 20:42:57.487: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet ha s invalid spi for destaddr=68.179.122.29, prot=50,  Mar 3, 2011 4. Synchronizing IPSEC VPN and failover. 5. Conventions.

Dec 18, 2020 · In the last three days our core router (Cisco 7609) has logged the following events: Dec 16 19:04:59.027 CST: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=, prot=50, spi=0xEF7ED795(4018067349), srcaddr=68.180.160.18, input interface=Vlan20 Dec 16 20:41:47.822 CST: %CRYPTO-4-RECVD_PKT_INV_SPI Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886), srcaddr=10.1.1.1. 注: NAT-T では、Cisco Bug ID CSCsq59183 が修正されるまでは RECVD_PKT_INV_SPI メッセージが正しく報告されません。 If you update your Cisco.com account with your WebEx/Spark email address, you can link your accounts in the future (which enables you to access secure Cisco, WebEx, and Spark resources using your WebEx/Spark login) Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886), srcaddr=10.1.1.1 . And it simply means that IPsec SA's are out of sync between the peers. Dec 03, 2016 · Dec 2 16:22:02.334: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec’d IPSEC packet has invalid spi for destaddr=12.12.12.2, prot=50, spi=0x End result : Traffic is being blackholed.

XX.XX failed its sanity check or is malformed 012283: Jan 10 04:19:49.255: %CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from XX.XX. XX.XX Hi. I am getting the message below on R5. Please help me out. Thanks. r5# *Oct 14 20:12:46.455: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=169.254.100.5, prot=50, spi=0x7771A053(2003935315), srcaddr=169.254.100.1, input interface=FastEthernet0/1.100 : %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr. my VPN is up but sometimes this message appears my current version: Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.3(3)M, RELEASE SOFTWARE (fc2) I Follow the procedures in this document but the problem persists.

237 eur na gbp
paypal nie je k dispozícii
logo dogecoin pes
dnešné správy
férová cena herndon
b je pre zostavenie brz
nábytok sprintz

60 良くあるお問い合わせ事例 ~%RECVD_PKT_INV_SPI 概要 出力されるログ % CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi 

my VPN is up but sometimes this message appears my current version: Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.3(3)M, RELEASE SOFTWARE (fc2) I Follow the procedures in this document but the problem persists. 012281: Jan 10 04:17:34.846: %CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from XX.XX. 58.37 failed its sanity check or is malformed 012282: Jan 10 04:18:48.573: %CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from XX.XX. XX.XX failed its sanity check or is malformed 012283: Jan 10 04:19:49.255: %CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from XX.XX.

Apr 30, 2009 · Hi, There is a common misconception of what the command crypto isakmp invalid-spi-recovery actually does. Even without this command, IOS already performs a kind of invalid SPI recovery functionality by sending a DELETE notify for the SA received to the sending peer if it already has an IKE SA with that peer.

Sometimes they "hang 27.07.2010 %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec’d IPSEC packet has invalid spi for destaddr=125.45.67.22, prot=50, spi=0x32040000(839122944), srcaddr=134.56.78.10, input interface=Ethernet0/0.125 解决问题。。。 实验环境:穿越nat 出现上面的原因 那就是ipsec 的问题了 趁着这个机会好好学习 ipsec %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes authentication pre-share crypto isakmp key test address 0.0.0.0 0.0.0.0 crypto isakmp invalid-spi-recovery crypto ipsec transform-set DefaultCrypto esp-aes crypto 13.02.2018 Expereincing a perceived outage with WSS service. %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=.. decaps: rec'd IPSEC packet has invalid spi for destaddr=92.70.112.34, prot=5 0, spi=0x3671DAC8(913431240), srcaddr=213.194.32.98 22.05.2009 Some vlans cross switches that are not mine to manage and i have recived a notice stating that my lan ip (vrrp logical ip) is generating "%CRYPTO-4-RECVD_PKT_INV_SPI" errors on switch log. Vrrp itself is working as expected, router A is master and B is bacup. I'm trying to get IPSec to work on a VTI between two hosts sitting behind NAT. I can get IKE phase 2 to complete and the tunnel interfaces are up/up but when I try to ping the pro %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=169.254.100.5, prot=50, spi=0x929964D0(2459526352), srcaddr=169.254.100.2, input interface=Ethernet0/1.100 20.07.2008 23.07.2010 As a result, an encrypting device will encrypt traffic with SAs that its peer does not know about. These packets are dropped on the peer with this message logged to the syslog: Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet > %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid > spi for destaddr=192.168.107.1, prot=17, spi=0x32040000(839122944), > srcaddr=78.85.133.237 Find answers to IPSEC packet has invalid spi from the expert community at Experts Exchange Cisco Bug: CSCtd47420 - GETVPN - CRYPTO-4-RECVD_PKT_NOT_IPSEC reported for pkt not matching flow 19.09.2016 14.08.2008 : %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr.

Even without this command, IOS already performs a kind of invalid SPI recovery functionality by sending a DELETE notify for the SA received to the sending peer if it already has an IKE SA with that peer. Everyday I have a lot of this messages: 9317: Apr 28 03:00:16.709: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=89.175.xx.xx, prot=50, spi=0x6D715B56(1836145494), srcaddr=77.236.xx.xx Then Virtual Tunnel Interfaces begin to bounce UP-DOWN. Sometimes they "hang Note: On the Cisco Aggregation Services Routers (ASR) platform, the %CRYPTO-4-RECVD_PKT_INV_SPI messages were not implemented until Cisco IOS ® XE Release 2.3.2 (12.2 (33)XNC2). Sep 2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886), srcaddr=10.1.1.1 10 Helpful Reply %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 crypto isakmp policy 10 encr aes authentication pre-share crypto isakmp key test address 0.0.0.0 0.0.0.0 crypto isakmp invalid-spi-recovery crypto ipsec transform-set DefaultCrypto esp-aes crypto Jul 8 05:28:51.867 EDT: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=172.17.1.1, prot=50, spi=0x2F547061(794062945), %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.1.1.2, prot=50, spi=0xE6F73833(3874961459), srcaddr=2.200.2.200 Expereincing a perceived outage with WSS service. %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=.. entry number 955 : CRYPTO-4-RECVD_PKT_INV_SPI decaps: rec'd IPSEC packet has invalid spi for destaddr=92.70.112.34, prot=5 0, spi=0x3671DAC8(913431240), srcaddr=213 If an IPSec tunnel is established correctly, but the connection is dropped soon after and messages similar to the following appear in the logs: CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=1.2.3.4, prot=51, spi=0x1214F0D(18960141), srcaddr=5.6.7.8 it's worth trying to add the following commands to the configuration: crypto isakmp invalid-spi-recovery CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet has invalid spi for destaddr=192.168.2.10, prot=17, spi=0xC8555555(3361035605), srcaddr=x.x.x.x realdreams September 21, 2012 at 2:35 a.m.