Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

IPsec invalid SPI notification

More Information:

IPsec invalid SPI notification

You can enable automatic recovery when peers in a security association (SA) become unsynchronized. When peers become unsynchronized, this can cause the transmission of packets with invalid security parameter index (SPI) values and the dropping of those packets by the receiving peer. You can enable automatic recovery by using the new respond-bad-spi max-responses configuration statement, which appears under the hierarchy level [edit services ipsec-vpn ike policy]. This statement results in a resynchronization of the SAs.
Product / Application Software Introduced Release
MX5 Junos OS 13.3R4
MX10 Junos OS 13.3R4
MX40 Junos OS 13.3R4
MX80 Junos OS 13.3R4
MX104 Junos OS 13.3R4
MX240 Junos OS 13.3R4
MX480 Junos OS 13.3R4
MX960 Junos OS 13.3R4
MX2008 Junos OS 15.1F7
MX2010 Junos OS 13.3R4
MX2020 Junos OS 13.3R4