<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One cluster not establishing s2s tunnels - Invalid IKE SPI in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/261815#M51329</link>
    <description>&lt;P&gt;Thanks for letting us know!&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2025 23:19:56 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-04T23:19:56Z</dc:date>
    <item>
      <title>One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260573#M51101</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've got a star mesh community with 11 center gateway clusters and 5 satellite gateways.&amp;nbsp; A mix of 5000 and 3000 series (R81.20) and some Quantum Sparks (R81.10).&amp;nbsp; One of my center gateway clusters (3000) will not establish a tunnel with other gateways, with the exception of one of the Quantum Sparks.&amp;nbsp; I'm also using Harmony VPN and that tunnel is active.&lt;/P&gt;&lt;P&gt;On the problem cluster in SmartView Monitor, it shows a "Down" state to most other gateways, but will show "Up - Phase 1"&amp;nbsp; at times.&amp;nbsp; Looking at my other gateways/clusters to the problem cluster, it's similar - some show "Up - Phase 1" and others show "Down."&lt;/P&gt;&lt;P&gt;In the logs, outgoing connection attempts from the problem cluster are rejected with the message,&amp;nbsp;"Informational exchange: Sending notification to peer: Invalid IKE SPI IKE SPIs: 20cb86c6725e2650:e095fab9ae48e34d."&amp;nbsp; Incoming attempts from other gateways/clusters are rejected with the message, "Child SA exchange: Exchange failed: timeout reached."&lt;/P&gt;&lt;P&gt;I'm also seeing some drops on the VPN blade, with the active member of the problem cluster as the Origin.&amp;nbsp; There is little information - the destination is the problem cluster, but there is no source, service, etc.&amp;nbsp; The VPN Peer Gateway is one of my other gateways/clusters.&lt;/P&gt;&lt;P&gt;I've tried resetting the tunnel, rebooting the problem gateways, other gateways, pushing policy, updating to the latest Take (118), deleting SA's via "vpn tu" and even removing the problem cluster from the VPN community and adding it back, but nothing changes.&amp;nbsp; And it's driving me crazy that one tunnel gets established without an issue...&lt;/P&gt;&lt;P&gt;I should note that I don't know when this started.&amp;nbsp; We have SD-WAN appliances at most of these sites, including the problem site, and traffic is routed through those as a primary, with the CP tunnels as backup.&amp;nbsp; So nobody would really notice if the tunnel is down.&lt;/P&gt;&lt;P&gt;My next step is to open a ticket, but thought I'd ask here first.&amp;nbsp; Thanks all.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 14:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260573#M51101</guid>
      <dc:creator>Jamie_Kelahan</dc:creator>
      <dc:date>2025-10-22T14:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260580#M51102</link>
      <description>&lt;P&gt;I would start with traffic capture and drops on both sides&lt;BR /&gt;&lt;BR /&gt;1. tcpdump -nnei ethX host x.x.x.x&lt;BR /&gt;(replace ethX with eth name of the outgoing interface facing the peer). replace x.x.x.x with the peer IP which the tunnel is negotiated to.)&lt;BR /&gt;*you can save it to a file by adding: -w /var/log/tcpdump.pcap&amp;nbsp; &amp;nbsp; to the end of the command&lt;BR /&gt;&lt;BR /&gt;2. fw monitor -F "0,0,&amp;lt;peerip&amp;gt;,0,0" -F "&amp;lt;peerip&amp;gt;,0,0,0,0"&lt;BR /&gt;(replace peerip with actual peer IP address)&lt;BR /&gt;*you can save it to a file by adding: -o /var/log/fwmon.pcap&amp;nbsp; &amp;nbsp; &amp;nbsp;at the end of the command&lt;/P&gt;
&lt;P&gt;3. fw ctl zdebug + drop&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*you can save it to a file by adding:&amp;nbsp; &amp;gt;&amp;gt; zdebugdrop.txt&amp;nbsp; &amp;nbsp; at the end of the command&lt;/P&gt;
&lt;P&gt;see if all ike packets are reaching properly side to side and no drops on ike packets.&lt;BR /&gt;&lt;BR /&gt;if it's a cluster, make sure the traffic is NATTED properly from phydical IP to VIP, and vice versa (in fw monitor), and that there is no NAT applied on the source IP/PORT (except for NAT TO VIP source IP if cluster)&lt;BR /&gt;&lt;BR /&gt;if all packets reaching properly side to side, enable vpn debug, and open it with IkeView or let TAC handle it.&lt;BR /&gt;&lt;BR /&gt;BTW, Checkpoint has SD-WAN product already, so you may consider unifying solutions if that suits your needs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 15:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260580#M51102</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2025-10-22T15:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260622#M51124</link>
      <description>&lt;P&gt;I second what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86692"&gt;@AmirArama&lt;/a&gt;&amp;nbsp; had duggested.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 19:22:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260622#M51124</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-22T19:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260633#M51130</link>
      <description>&lt;P&gt;Thanks for the suggestions.&amp;nbsp; I haven't had much time to get into this today, but I did some packet captures.&amp;nbsp; tcpdump appears to be fine as I see traffic and acks.&amp;nbsp; fw monitor capture has a lot of malformed packets.&amp;nbsp; I compared to another fw monitor capture between the broken site and the one it actually has a tunnel established to and don't see those malformed packet messages, so I don't know what that means.&lt;/P&gt;&lt;P&gt;zdebug shows "dropped by fwhold_expires Reason: held chain expired" errors on the broken side and "dropped by vpn_drop_and_log Reason: Failure preparing tunnel creation, internal error" on the peer side.&lt;/P&gt;&lt;P&gt;Again, I didn't have a lot of time to spend on it today, but will continue digging.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 22:35:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260633#M51130</guid>
      <dc:creator>Jamie_Kelahan</dc:creator>
      <dc:date>2025-10-22T22:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260634#M51131</link>
      <description>&lt;P&gt;And I'm not sure what you mean by it being NATTED properly in fw monitor?&amp;nbsp; They are both clusters and I see traffic to/from the public VIP addresses.&amp;nbsp; Is there something more I should be looking for?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 22:38:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260634#M51131</guid>
      <dc:creator>Jamie_Kelahan</dc:creator>
      <dc:date>2025-10-22T22:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260704#M51139</link>
      <description>&lt;P&gt;You should see all 4 inspection points and if you do NOT see big O for post outbound, I believe that would imply traffic is encrypted, but capture should also show you if its natter. Be free to refer to this great site my colleague made while ago.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tvpdump101.com" target="_blank" rel="noopener"&gt;https://tcpdump101.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Not sure why takes me to tvpdump101, but its tcpdump101.com&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 15:16:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260704#M51139</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-23T15:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260744#M51153</link>
      <description>&lt;P&gt;Can you see any logs containing "key install"? That may give us clue when issue may had happened.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 20:05:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260744#M51153</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-23T20:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260840#M51192</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Please let us know how this gets resolved.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Oct 2025 09:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/260840#M51192</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-25T09:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/261813#M51328</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Sorry for the lack of response.&amp;nbsp; As I mentioned, this is not the primary VPN for this site and I had higher priority issues come up.&lt;/P&gt;&lt;P&gt;It's a long story, but the end result is that this turned out to be an issue with the ISP's equipment.&lt;/P&gt;&lt;P&gt;Thanks again for all the help.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 23:04:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/261813#M51328</guid>
      <dc:creator>Jamie_Kelahan</dc:creator>
      <dc:date>2025-11-04T23:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: One cluster not establishing s2s tunnels - Invalid IKE SPI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/261815#M51329</link>
      <description>&lt;P&gt;Thanks for letting us know!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2025 23:19:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-cluster-not-establishing-s2s-tunnels-Invalid-IKE-SPI/m-p/261815#M51329</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-04T23:19:56Z</dc:date>
    </item>
  </channel>
</rss>

