> Source: [sk185147](https://support.checkpoint.com/results/sk/sk185147)

# sk185147 - VPN traffic drops during IKE rekeys with "failed to insert entry to ikesa spi table" errors

| Property | Value |
|----------|-------|
| Solution ID | sk185147 |
| Date Created | 2026-07-14 |
| Last Modified | 2026-07-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * One or more VPN tunnels on the same Security Gateway or Virtual System (VS) intermittently stop passing traffic, although the tunnel(s) appear to be established.

* The output of the "`fw ctl zdebug drop`" debug command on the Security Gateway shows this error message:  

  `ike_esp_add_by_fields: ERROR: failed to insert entry to ikesa spi table`

## Cause

Excessive IKE/IPsec rekey activity from a VPN peer can exhaust the kernel Security Parameter Index (SPI) tables. When the SPI tables reach their limits, new inbound or outbound Security Associations (SAs) cannot be registered successfully.

As a result, IKE negotiations may appear successful in user space, while the kernel is unable to correctly associate traffic with the corresponding SAs. This condition can cause intermittent VPN traffic failures, encryption failures, or decryption failures.

Example Scenario:

1. The VPN peer repeatedly initiates child SA rekeys at a very high rate
2. The Security Gateway attempts to register new inbound and outbound SPIs in the kernel tables
3. The SPI tables become exhausted.
4. New SA registrations fail.
5. IKE negotiation may still appear complete in user space, but the kernel cannot properly map the SAs

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
