Skip to main content
pkc
New Member
October 19, 2015
Question

site to site with cisco asa - Unknown SPI

  • October 19, 2015
  • 0 replies
  • 1798 views

Hi,

 

I'm stuck while trying to have a vpn site to site work between my fortigate vm 04 running 5.2.4 and a cisco asa device.

 

The vpn ends on a VDOM on a loopback.

 

I checked the parameters several times, phase1 and phase2 are correct, but when the remote site sends traffic, the fortigate

drops it with "unknown spi " showing the spi ID that is listed when I list the active phase 2 tunnels. 

 

Cisco device shows correct phase1 and phase2, but traffic is still dropped. 

 

Is there a known issue related to fortios 5.2.4 and cisco asa ?

 

Are there some incompatibilities ?

 

thanks.

 

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!