> Source: [sk176957](https://support.checkpoint.com/results/sk/sk176957)

# sk176957 -  IKEV2 Site to Site tunnel from Check Point to 3rd party is randomly dropped with "Invalid SPI" error

| Property | Value |
|----------|-------|
| Solution ID | sk176957 |
| Date Created | 2022-01-02 |
| Last Modified | 2026-06-25 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * An IKEV2 Site to Site tunnel from a Check Point Security Gateway to a 3rd-party peer is randomly dropped with an "`Invalid SPI`" error message.
* The *ikev2.xmll* file shows that the Check Point Security Gateway sends many "`Invalid SPI`" messages after the 3rd-party peer rekeys the SPI.
* The *vpnd.elg* file shows:   
  `Sending notification to peer: Invalid SPI : xxxxxxxxx.`

## Cause

Before the Check Point Security Gateway updates the kernel parameter i*nSPI_by_instance*in all instances, an encrypted packet arrives from the 3rd-party peer. This packet is handled by the wrong instance.

## Solution

This problem was fixed. The fix is included starting from:

* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152&partition=Basic&product=Endpoint) since Take 237
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456&partition=Basic&product=All) since Take 114
* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114&partition=Basic&product=All) since Take 34
* [Check Point R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)

Check Point recommends to always upgrade to the most recent version   
([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).  

**Related Solution:** [sk108600 - VPN Site-to-Site with 3rd party](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
