Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
biskit
Advisor
Jump to solution

VPN drops - decrypt mspi is not valid

I have a site-to-site VPN from CP to AWS.  It has been working fine, then suddenly it stopped working.  No changes have been made.

The tunnel itself is up.

I initiate traffic from my LAN to AWS.  I'm seeing return traffic dropping as it comes back from AWS.  Zdebug shows the following:

 

Line 10860: @;667035602;[cpu_0];[SIM-241633670];vpn_verify: mspi check failed (cdir=1; conn_mspis:000004e4,00000000; packet_mspi:003ba7df), c2s conn: <10.16.173.13,62106,10.51.25.146,1521,6>;
Line 10861: @;667035603;[cpu_0];[SIM-241633670];do_inbound: VPN verify returned DROP -> dropping packet, conn: <10.51.25.146,1521,10.16.173.13,62106,6>;
Line 10862: @;667035603;[cpu_0];[SIM-241633670];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:<10.51.25.146,1521,10.16.173.13,62106,6>;
Line 10863: @;667035603;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 10.51.25.146:1521 -> 10.16.173.13:62106 dropped by vpn_dec_verify_mspi_failure_sxl_notification_handler Reason: decrypt mspi is not valid;

 

I can't see much in SecureKnowledge on this error.  Has anyone come across this before?  Any ideas on why it's suddenly started happening?  I've dropped the tunnel (in "vpn tu") and it comes straight back up fine, but still drops return traffic.

0 Kudos
1 Solution

Accepted Solutions
biskit
Advisor

We've deleted the AWS VPN config and recreated it from scratch.  Updated the new AWS peer IP's in Check Point and the VPN is back up and working again.  Still not sure what was causing the errors but recreating was quicker than debugging!

View solution in original post

(1)
4 Replies
G_W_Albrecht
Legend Legend
Legend

I would suggest that you contact CP TAC to get this resolved asap !

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
0 Kudos
biskit
Advisor

Yeah I already have.  Their suggestions aren't especially useful at the moment so I thought I'd throw it out to the wider community just in case 😀.  I'll carry on with TAC.

(1)
biskit
Advisor

We've deleted the AWS VPN config and recreated it from scratch.  Updated the new AWS peer IP's in Check Point and the VPN is back up and working again.  Still not sure what was causing the errors but recreating was quicker than debugging!

(1)
the_rock
Legend
Legend

I know what you mean...I found myself doing simlar with different issues, rather than waiting on TAC, simply due to urgency of the matter.

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events