> Source: [sk172648](https://support.checkpoint.com/results/sk/sk172648)

# sk172648 - IKEv2 negotiation fails between a Spark Firewall and a VPN peer in Azure / AWS

| Property | Value |
|----------|-------|
| Solution ID | sk172648 |
| Date Created | 2021-03-21 |
| Last Modified | 2024-07-11 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 910 |

## Symptoms

- The "VPN" log on the Quantum Spark Appliance shows one of these messages in the "Description" section:

* `IKE failure: Informational exchange: Sending notification to peer: Invalid IKE SPI`

  Example:

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1616324252844/IKEv2 limitation202103211307321.jpg)
* `Received CCSA request with an IKE SA that is not authenticated`  
  `
  Could not allocate inbound Create Child SA exchange`

## Cause

Due to IKEv2 limitations, certificate authentication and renegotiation for the support for Azure/AWS is limited for:

* Certificate authentication

* Renegotiation

## Solution

No fix is required; the system is functioning as designed.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
