cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1204
Views
0
Helpful
2
Replies

FTD 2130 via FMC - Enable IkeV2 on second outside interface

Lee Dress
Level 1
Level 1

I have 2 outside connections to my 2130 and some static routing to point certain things in certain directions. 

 

My secondary outbound interface has all of my site to site tunnels on it. 

 

I have tried to move one device's tunnel to the primary outbound interface, but it always fails.  Do I have to do something special to enable ikev2 on this interface? 

My ASA 5516 allowed me to build tunnels on both interfaces. 

 

here is the error

 

FMC >> crypto ikev2 enable nitel
fpr-1 >> [error] : ERROR: Failed to open "udp/localized/2/4500"
ERROR: Error opening IKE port 4500 on Interface nitel
Config Error -- crypto ikev2 enable nitel

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

It's possible you have an existing connection through the firewall that's using udp/4500. Clear the connections and xlates and try to deploy (unless there's a static NAT in place).

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

It's possible you have an existing connection through the firewall that's using udp/4500. Clear the connections and xlates and try to deploy (unless there's a static NAT in place).

we have a Verizon 4g network extender doing a PAT on that port.  I will hve to see if I can move it off the network.

 

Thank you for saving me hours of searching...

Review Cisco Networking for a $25 gift card