<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN drops - decrypt mspi is not valid in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187914#M34647</link>
    <description>&lt;P&gt;I know what you mean...I found myself doing simlar with different issues, rather than waiting on TAC, simply due to urgency of the matter.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 18:54:24 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-07-27T18:54:24Z</dc:date>
    <item>
      <title>VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187809#M34631</link>
      <description>&lt;P&gt;I have a site-to-site VPN from CP to AWS.&amp;nbsp; It has been working fine, then suddenly it stopped working.&amp;nbsp; No changes have been made.&lt;/P&gt;&lt;P&gt;The tunnel itself is up.&lt;/P&gt;&lt;P&gt;I initiate traffic from my LAN to AWS.&amp;nbsp; I'm seeing return traffic dropping as it comes back from AWS.&amp;nbsp; Zdebug shows the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Line 10860: @;667035602;[cpu_0];[SIM-241633670];vpn_verify: mspi check failed (cdir=1; conn_mspis:000004e4,00000000; packet_mspi:003ba7df), c2s conn: &amp;lt;10.16.173.13,62106,10.51.25.146,1521,6&amp;gt;;
Line 10861: @;667035603;[cpu_0];[SIM-241633670];do_inbound: VPN verify returned DROP -&amp;gt; dropping packet, conn: &amp;lt;10.51.25.146,1521,10.16.173.13,62106,6&amp;gt;;
Line 10862: @;667035603;[cpu_0];[SIM-241633670];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:&amp;lt;10.51.25.146,1521,10.16.173.13,62106,6&amp;gt;;
Line 10863: @;667035603;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 10.51.25.146:1521 -&amp;gt; 10.16.173.13:62106 dropped by vpn_dec_verify_mspi_failure_sxl_notification_handler Reason: decrypt mspi is not valid;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see much in SecureKnowledge on this error.&amp;nbsp; Has anyone come across this before?&amp;nbsp; Any ideas on why it's suddenly started happening?&amp;nbsp; I've dropped the tunnel (in "vpn tu") and it comes straight back up fine, but still drops return traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 08:39:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187809#M34631</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-07-27T08:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187817#M34632</link>
      <description>&lt;P&gt;I would suggest that you contact CP TAC to get this resolved asap !&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187817#M34632</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-27T10:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187819#M34633</link>
      <description>&lt;P&gt;Yeah I already have.&amp;nbsp; Their suggestions aren't especially useful at the moment so I thought I'd throw it out to the wider community just in case&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;.&amp;nbsp; I'll carry on with TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:38:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187819#M34633</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-07-27T10:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187845#M34637</link>
      <description>&lt;P&gt;We've deleted the AWS VPN config and recreated it from scratch.&amp;nbsp; Updated the new AWS peer IP's in Check Point and the VPN is back up and working again.&amp;nbsp; Still not sure what was causing the errors but recreating was quicker than debugging!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:33:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187845#M34637</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-07-27T12:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187914#M34647</link>
      <description>&lt;P&gt;I know what you mean...I found myself doing simlar with different issues, rather than waiting on TAC, simply due to urgency of the matter.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 18:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/187914#M34647</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-27T18:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/258776#M50750</link>
      <description>&lt;P&gt;&lt;SPAN&gt;In case anyone else searches this error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Same symptoms for UDP traffic passing over VPN being silently dropped on arrival after decrypt but zdebug:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;@;1531076470.3303760;[vs_0];[tid_40];[fw4_40];fw_log_drop_ex: Packet proto=SRC:6440 -&amp;gt; DST:6440 dropped by vpn_dec_verify_mspi_failure_sxl_notification_handler Reason: decrypt mspi is not valid;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Same SRC and DST using different ports worked so was not a VPN issue.&lt;/P&gt;&lt;P&gt;Matching Connections flushed from table and connectivity restored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 10:27:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/258776#M50750</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2025-10-02T10:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN drops - decrypt mspi is not valid</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/258779#M50753</link>
      <description>&lt;P&gt;Excellent!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 10:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-drops-decrypt-mspi-is-not-valid/m-p/258779#M50753</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-02T10:48:31Z</dc:date>
    </item>
  </channel>
</rss>

