IKE/4/IKE_EXIST_IPSEC_SA_REKEY_FAIL

Message

IKE/4/IKE_EXIST_IPSEC_SA_REKEY_FAIL: Existing IPsec SA rekey failed. (VrfName=[VrfIndex], LocalIp=[LocalIp], PeerIp=[PeerIp], PolicyName=[PolicyName], InterfaceName=[IfIndex], ConnectionId=[ConnectionId], SrcIp=[SrcIp], DstIp=[DstIp], AclNumber=[AclNumber], AclName=[AclName])

In VS mode, this log is supported only by the admin VS.

Description

The existing IPsec SA key failed to be updated.

Parameters

Parameter Name Parameter Meaning

VrfIndex

VPN instance name

LocalIp

Local IP address

PeerIp

Peer IP address

PolicyName

IPsec policy name

IfIndex

Interface name

ConnectionId

Security association ID

SrcIp

Source IP address

DstIp

Destination IP address

AclNumber

ACL number

AclName

ACL Name

Possible Causes

The IKE configurations on communication peers changed, which caused their configurations to be different.

The connection between communication peers was abnormal.

Procedure

1. Ensure the connection between communication peers is normal.

2. Check whether the IKE configurations on communication peers change.

3. Collect log information and configuration information, and then contact technical support personnel.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >