Professional Documents
Culture Documents
IPSEC Tunnel Is Flapping
IPSEC Tunnel Is Flapping
62289
Created On 09/26/18 21:06 PM - Last Modified 08/15/23 06:19 AM
VPNS
PAN-OS
Symptom
Environment
Cause
One of the reasons for the tunnel flapping or not passing traffic is if the SPI number is not stable.
This could be caused by a mismatch in the IKE/IPSEC configuration due to which the tunnel would rekey
multiple times
A security association is uniquely identified by a triple consisting of a Security Parameter Index (SPI), an IP
Destination Address, and a security protocol (AH or ESP) identifier. SPI is arbitrary 32-bit value that is used by a
receiver to identify the SA to which an incoming packet should be bound. The SPI is provided to map the incoming
packet to an SA at the destination.
The SPI number should remain stable until a tunnel renegotiates. If this number is changing, then the tunnel
will not be stable.
Resolution