🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)60 / 128
Question 60 of 128

An engineer manages a route-based IPsec VTI tunnel from an on-premises Cisco IOS XE router to an Azure VPN Gateway. The tunnel came up successfully, but after several hours users report intermittent loss of connectivity to Azure workloads. On the IOS XE router, 'show crypto ikev2 sa' shows the SA state flapping between READY and DELETING, and the logs contain repeated 'IKEv2-ERROR: Received INVALID_SPI notify' messages. Ping traffic recovers only after a manual 'clear crypto ikev2 sa'. What is the MOST likely cause of this behavior?

Reviewed for accuracy · Report an issueNext question