<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD VPN strong crypto not support in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839195#M102984</link>
    <description>&lt;P&gt;Do you have your appliance (or the managing FMC) registered in your Smart license account?&lt;/P&gt;
&lt;P&gt;If so, you can request Cisco add the 3DES-AES license for it.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2019 04:15:32 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-04-16T04:15:32Z</dc:date>
    <item>
      <title>FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3838268#M102978</link>
      <description>&lt;P&gt;Hi There, I am having FTD 2100 appliance managed through FMC appliance and recently implemented, when i tried to created IPSEC tunnel to remote site, while deploying the policy, its creating error. as like below. inputs on this is highly appriciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Strong crypto (i.e encryption algorithm greater than DES) for VPN topology xxx_VPN is not supported. This can be because of FMC is running on evaluation license or smart licensing is not entitled for storng crypto. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, how to i verify my FMC is not running evaluation license and how to activate smart licensing for strong crypto.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3838268#M102978</guid>
      <dc:creator>Sureshkumar B</dc:creator>
      <dc:date>2020-02-21T17:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839195#M102984</link>
      <description>&lt;P&gt;Do you have your appliance (or the managing FMC) registered in your Smart license account?&lt;/P&gt;
&lt;P&gt;If so, you can request Cisco add the 3DES-AES license for it.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 04:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839195#M102984</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-04-16T04:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839372#M102991</link>
      <description>Hi, I have Appliance for management server as well and registered in smart licensing. Please let me know 3DES-AES encryption requires separate license in FTD.</description>
      <pubDate>Tue, 16 Apr 2019 10:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839372#M102991</guid>
      <dc:creator>Sureshkumar B</dc:creator>
      <dc:date>2019-04-16T10:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839433#M102992</link>
      <description>&lt;P&gt;I just checked my company Smart Account and see that we don't have a separate strong crypto (3DES-AES) license for FTD devices. There doesn't appear to be any global setting in the account that enables Strong Crypto either. (Or if there is it's not exposed to an account admin (me).)&lt;/P&gt;
&lt;P&gt;I recommend opening a case via email to licensing@cisco.com to have then check your account settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 12:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839433#M102992</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-04-16T12:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839445#M102996</link>
      <description>&lt;P&gt;Looks like you did not enable export-control features when registering the device via FMC using smart licensing. When you register the FMC using a token, make sure the "Allow export control" checkbox is checked.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="export-control.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/34778i45533989C65AD615/image-size/large?v=v2&amp;amp;px=999" role="button" title="export-control.PNG" alt="export-control.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you do this, your FTD device should have this enabled under the FMC:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="export-control-2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/34779i68439F840E7FEE31/image-size/large?v=v2&amp;amp;px=999" role="button" title="export-control-2.PNG" alt="export-control-2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What you need to do is re-register the FMC again to smart licensing, this time with export control enabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 12:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839445#M102996</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2019-04-16T12:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839447#M102998</link>
      <description>&lt;P&gt;Good catch Rahul, thanks for posting that one.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 12:42:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839447#M102998</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-04-16T12:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN strong crypto not support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839571#M103002</link>
      <description>If i do re-registering, will it have any production impact or any other licensing issue will occur. Allow export-controlled functionaility on the products registered with this token</description>
      <pubDate>Tue, 16 Apr 2019 15:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-strong-crypto-not-support/m-p/3839571#M103002</guid>
      <dc:creator>Sureshkumar B</dc:creator>
      <dc:date>2019-04-16T15:06:35Z</dc:date>
    </item>
  </channel>
</rss>

