"The Security Parameter Index (SPI) is an identification tag added to the header while using IPsec for tunneling the IP traffic. This tag helps the kernel discern between two traffic streams where different encryption rules and algorithms may be in use."
So it looks like either;
1. the tunnel was setup but it has expired on your end, or
2. its a stray packet for something else
If #1, then check that the timer and data volume rekeying parameters are the same on both ends of the tunnel
If #2, do the endpoint IPs match?
My first guess would be that you have a shorter timer on your IPSec SAs than the remote end has, but usually tunnels fail to setup when parameters dont match. I have no experience with Forti IPSec...