08-27-2025 02:26 PM
Hi Team,
I've configured Route Based IPSec Site-to-Site VPN according to the guide: Configure Route Based Site to Site VPN Tunnel on FTD Managed by FMC - Cisco
When I deploy the config, I'm getting the following error:
Refer to the following troubleshooting information when contacting Cisco TAC. Lina messages FMC >> clear configuration session FMC >> strong-encryption-disable FMC >> no dp-tcp-proxy FMC >> crypto ikev2 policy 1 FMC >> encryption AES-256 FTDv1 >> error : encryption AES-256 ^ ERROR: % Invalid input detected at '^' marker. Config Error -- encryption AES-256 Other logs Lina config ROLLBACK failure log Lina configuration application failure. Error in lina apply phase due to Config Error response from LINA Rollback skipped as Lina and SNORT are in sync Write mem executed as Lina and SNORT are in sync Lina write mem operation successful Note:Deployment is successful in Control Node/Active unit. Deployment is skipped/incomplete on Data nodes due to one of theI've tried with an IKEv1 policy and it fails as well.
Solved! Go to Solution.
08-27-2025 03:28 PM
Strong encrypt is need license which is free from cisco and available in FTD
But there are some bug about fmc push this feature disable to ftd' this with use AES-256 is prevent VPN from be active.
So as workaround use other cipher like aes-128 and open TAC' it can bug.
MHM
08-27-2025 02:32 PM
FMC >> strong-encryption-disable
You use AES-256 and strong encrypt is disable' you need to enable it
MHM
08-27-2025 02:39 PM
As workaround use AES-128
And open TAC
MHM
08-27-2025 03:25 PM
Looks like doesn´t like it either..
I'll keep playing a little bit more to see if I can find a combo that works. And I'll keep TAC option as well. Thanks for your help!
Refer to the following troubleshooting information when contacting Cisco TAC.
Lina messages
FMC >> clear configuration session
FMC >> strong-encryption-disable
FMC >> no dp-tcp-proxy
FMC >> crypto ikev2 policy 1
FMC >> encryption AES
FTDv1 >> error :
encryption AES
^
ERROR: % Invalid input detected at '^' marker.
Config Error -- encryption AES
Other logs
Lina config ROLLBACK failure log
Lina configuration application failure. Error in lina apply phase due to Config Error response from LINA
08-27-2025 03:35 PM
What is ftd and fmc ver?
MHM
08-27-2025 04:49 PM
Version 7.4.2 (Build 172)
08-27-2025 02:48 PM - edited 08-27-2025 02:50 PM
Thanks much for that quick reply!! Double checked my config and I'm still wondering what´s the FMC option/config that ends up adding that config statement (strong-encryption-disable)..?
Is it dependent on how I create IKEv2 policy?
This is how my IKEv2 policy looks like:
08-27-2025 03:28 PM
Strong encrypt is need license which is free from cisco and available in FTD
But there are some bug about fmc push this feature disable to ftd' this with use AES-256 is prevent VPN from be active.
So as workaround use other cipher like aes-128 and open TAC' it can bug.
MHM
08-27-2025 03:54 PM - edited 08-27-2025 03:56 PM
Confirmed, if I use weakest option (Encryption DES, do not tell security team! It's a lab environment anyways!!)
Thanks again!
08-27-2025 03:55 PM
You are so welcome
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide