Description | This article describes a specific scenario where, due to an HA split-brain scenario, an IPsec tunnel flaps and repeated rekey/ESP SPI mismatches are noticed. |
Scope | FortiGate HA. |
Solution |
If repeated Received ESP packets with unknown SPI entries are observed in the event log, one possible cause to verify is that the HA cluster state is broken (split-brain), causing independent rekey events and mismatched SPIs.
The most common symptoms to look for:
Reasons why it happens: When the HA heartbeat/link fails, the cluster can enter a split-brain (both members think they are primary). Each unit may then independently manage SAs and trigger rekeys. An ESP packet is accepted only if its SPI matches an active IPsec Security Association (SA).
If an endpoint has rekeyed and changed SPIs while the peer still uses the old SA, the peer will drop incoming ESP packets as 'unknown SPI'. In an HA split-brain (heartbeat/link failure) both cluster members can behave as primaries and independently manage SAs/rekeys, producing mismatched keys/SPIs and repeated tunnel teardowns.
To determine if an HA split-brain is the root cause, the following can be checked:
get system ha status
get vpn ipsec tunnel summary
diagnose debug reset
Prevention and Best Practices:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.