A user is experiencing 'No valid SA' errors when attempting to send traffic over a site-to-site VPN. What is the most likely cause?
If the existing SA has expired due to lifetime limits and the rekeying negotiation fails, the gateway will no longer have a valid mapping for that traffic. Consequently, the gateway discards the traffic, resulting in the 'No valid SA' error in the VPN debug logs.
Why this answer
The 'No valid SA' error indicates that the gateway has received traffic intended for a VPN tunnel, but it lacks an active IPsec Security Association (SA) to handle that specific traffic. This often occurs due to tunnel timeouts, rekeying failures, or routing issues where the traffic is reaching the gateway before the tunnel is fully established or after it has expired.
Exam trap
Candidates assume 'No valid SA' errors indicate permanent pre-shared key mismatches, missing that expired tunnels or failed rekey attempts frequently cause temporary SA absences.