Hi @Pavel88,
MSPI is a tunnel identifier. It is a local counter that uniquely identifies a tunnel on the given machine. MSPI is an index to the MSA (Meta SA), which contains fields common to all SAs with the same peer, methods, and IDs. When a new IPsec tunnel is established, a new MSPI is created by it, and it gets the next free MSPI number. The MSPI counter is then increased.
I think there is something incorrect with the MSPI update in the encryption process.
I would open a TAC case.
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips