SOLVED

Azure VPN with Cisco ASA 5545

%3CLINGO-SUB%20id%3D%22lingo-sub-158621%22%20slang%3D%22en-US%22%3EAzure%20VPN%20with%20Cisco%20ASA%205545%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-158621%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20everyone!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20hope%20you%20can%20help%2C%20I%20have%20a%20partner%20just%20setup%20the%20VPN%20on%20the%20Azure%20portal%20to%20the%20Cisco%20ASA%205545%2C%20he%20have%20used%20the%20script%20template%20provide%20by%20Microsoft%20to%20configure%20the%20VPN%20from%20Azure%20to%20our%20office.%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CDIV%20class%3D%22msportalfx-text-header-regular%22%20data-bind%3D%22text%3A%20availabilityString%22%3EUnavailable%3C%2FDIV%3E%0A%3CP%3EHowever%20when%20I%20close%20the%20tunnel%20an%20error%20message%20is%20displayed%20on%20the%20azure%20side.%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EThe%20connection%20cannot%20establish%20due%20to%20security%20policy%20(IPsec%2FIKE)%20policy%20mismatch%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EOn%20the%20side%20of%20the%20Cisco%20ASA%20firewall%20displays%20the%20following%20message.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EIKEv2%20Tunnel%20rejected%3A%20Crypto%20Map%20Policy%20not%20found%20for%20the%20remote%20traffic%20selector%200.0.0.0%2F255.255.255.255%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EAny%20assistance%20would%20be%20great.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ESincerely%2C%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ELeonardo%20Foga%C3%A7a%20de%20Almeida%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-158621%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-164934%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VPN%20with%20Cisco%20ASA%205545%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-164934%22%20slang%3D%22en-US%22%3E%3CP%3EI%20forgot%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20was%20the%20article%20i%20used%20for%20reference.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-ipsecikepolicy-rm-powershell%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-ipsecikepolicy-rm-powershell%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESincered%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ELeonardo%20Foga%C3%A7a%20de%20Almeida%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-164931%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VPN%20with%20Cisco%20ASA%205545%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-164931%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Dave.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20opened%20a%20call%20at%20Microsoft%20and%20customized%20the%20powershell%20commands%20with%20my%20customer's%20Cisco%3CBR%20%2F%3EI%20ran%20the%20following%20powershell%20command%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%24ipsecpolicy6%20%3D%20New-AzureRmIpsecPolicy%20-IkeEncryption%20AES256%20-IkeIntegrity%20SHA1%20-DhGroup%20DHGroup2%20-IpsecEncryption%20AES256%20-IpsecIntegrity%20SHA1%20-PfsGroup%20None%20-SALifeTimeSeconds%203600%20-SADataSizeKilobytes%20102400000%3C%2FP%3E%0A%3CP%3E%24GWName1%20%3D%20%22xxxxxxx%22%3CBR%20%2F%3E%24RG1%20%3D%20%22xxxxx%22%3CBR%20%2F%3E%24LNGName6%20%3D%20%22xxxxx%22%3CBR%20%2F%3E%24Connection16%20%3D%20%22xxxxx%22%3CBR%20%2F%3E%24Location1%20%3D%20%22xxxxx%22%3C%2FP%3E%0A%3CP%3E%24vnet1gw%20%3D%20Get-AzureRmVirtualNetworkGateway%20-Name%20%24GWName1%20-ResourceGroupName%20%24RG1%3CBR%20%2F%3E%24lng6%20%3D%20Get-AzureRmLocalNetworkGateway%20-Name%20%24LNGName6%20-ResourceGroupName%20%24RG1%3C%2FP%3E%0A%3CP%3ENew-AzureRmVirtualNetworkGatewayConnection%20-Name%20%24Connection16%20-ResourceGroupName%20%24RG1%20-VirtualNetworkGateway1%20%24vnet1gw%20-LocalNetworkGateway2%20%24lng6%20-Location%20%24Location1%20-ConnectionType%20IPsec%20-UsePolicyBasedTrafficSelectors%20%24True%20-IpsecPolicies%20%24ipsecpolicy6%20-SharedKey%20'xxxxx'%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EThese%20were%20the%20policies%20required%20on%20my%20customer%20Cisco%20ASA%205545%20running%20Software%20Version%209.6%20(2)%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%22saLifeTimeSeconds%22%3A%203600%2C%20%26nbsp%3B%20(This%20is%20phase%202%2C%20or%20what%20you%20should%20configure%20in%20Crypto%20Map%20settings%3B%20In%20the%20Cisco%20ASA%205545%2C%20it%20is%20represented%20as%201%3A00%3A00)%20%26nbsp%3B%20%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%22saDataSizeKilobytes%22%3A%20102400000%2C%26nbsp%3B%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3E%22ipsecEncryption%22%3A%20%22AES256%22%2C%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%22ipsecIntegrity%22%3A%20%22SHA1%22%2C%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%22ikeEncryption%22%3A%20%22AES256%22%2C%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%22ikeIntegrity%22%3A%20%22SHA1%22%2C%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%22dhGroup%22%3A%20%22DH-2%22%2C%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%22pfsGroup%22%3A%20%22NO%20PFS%22%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPhase%201%20lifetime%20seconds%20is%2028800%20(This%20is%20phase%201%2C%20which%20should%20be%20configured%20on%20the%20ASA%20under%20your%20IKEv2%20policy)%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EThanks%20to%20Daniel%20Pires%20from%26nbsp%3B%20for%20helping%20me%20figure%20this%20out!%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EI%20holp%20it%20helps%20you.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ESincered%2C%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ELeonardo%20Foga%C3%A7a%20de%20Almeida%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-164766%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VPN%20with%20Cisco%20ASA%205545%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-164766%22%20slang%3D%22en-US%22%3EWhat%20was%20it%20that%20fixed%20the%20issue%3F%20I%20am%20having%20the%20same%20problem.%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%3CBR%20%2F%3EDave%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-160639%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VPN%20with%20Cisco%20ASA%205545%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-160639%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Kasun!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20followed%20but%20the%20doc%20is%20outdated%2C%20I%20was%20able%20to%20solve%20the%20problem%20when%20I%20called%20open%20at%20Microsoft%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ELeonardo%20Foga%C3%A7a%20de%20Almeida%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-160309%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20VPN%20with%20Cisco%20ASA%205545%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-160309%22%20slang%3D%22en-US%22%3Efollowing%20is%20a%20doc%20for%20creating%20VPN%20with%20CISCO%20%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-3rdparty-device-config-cisco-asa%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-3rdparty-device-config-cisco-asa%3C%2FA%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello everyone!

 

I hope you can help, I have a partner just setup the VPN on the Azure portal to the Cisco ASA 5545, he have used the script template provide by Microsoft to configure the VPN from Azure to our office.

 

Unavailable

However when I close the tunnel an error message is displayed on the azure side.

The connection cannot establish due to security policy (IPsec/IKE) policy mismatch

 

On the side of the Cisco ASA firewall displays the following message.

IKEv2 Tunnel rejected: Crypto Map Policy not found for the remote traffic selector 0.0.0.0/255.255.255.255

 

Any assistance would be great.

 

Sincerely,

 

Leonardo Fogaça de Almeida

 

 

5 Replies

Hi Kasun!

 

I followed but the doc is outdated, I was able to solve the problem when I called open at Microsoft

 

Thanks.

 

Leonardo Fogaça de Almeida

What was it that fixed the issue? I am having the same problem.

Thanks
Dave
best response confirmed by Leonardo Almeida (New Contributor)
Solution

Hi Dave.

 

I opened a call at Microsoft and customized the powershell commands with my customer's Cisco
I ran the following powershell command:

 

$ipsecpolicy6 = New-AzureRmIpsecPolicy -IkeEncryption AES256 -IkeIntegrity SHA1 -DhGroup DHGroup2 -IpsecEncryption AES256 -IpsecIntegrity SHA1 -PfsGroup None -SALifeTimeSeconds 3600 -SADataSizeKilobytes 102400000

$GWName1 = "xxxxxxx"
$RG1 = "xxxxx"
$LNGName6 = "xxxxx"
$Connection16 = "xxxxx"
$Location1 = "xxxxx"

$vnet1gw = Get-AzureRmVirtualNetworkGateway -Name $GWName1 -ResourceGroupName $RG1
$lng6 = Get-AzureRmLocalNetworkGateway -Name $LNGName6 -ResourceGroupName $RG1

New-AzureRmVirtualNetworkGatewayConnection -Name $Connection16 -ResourceGroupName $RG1 -VirtualNetworkGateway1 $vnet1gw -LocalNetworkGateway2 $lng6 -Location $Location1 -ConnectionType IPsec -UsePolicyBasedTrafficSelectors $True -IpsecPolicies $ipsecpolicy6 -SharedKey 'xxxxx'

 

These were the policies required on my customer Cisco ASA 5545 running Software Version 9.6 (2)

 

"saLifeTimeSeconds": 3600,   (This is phase 2, or what you should configure in Crypto Map settings; In the Cisco ASA 5545, it is represented as 1:00:00)     

"saDataSizeKilobytes": 102400000,   
"ipsecEncryption": "AES256",       
 "ipsecIntegrity": "SHA1",    
 "ikeEncryption": "AES256",  
 "ikeIntegrity": "SHA1",     
 "dhGroup": "DH-2",     
 "pfsGroup": "NO PFS" 

Phase 1 lifetime seconds is 28800 (This is phase 1, which should be configured on the ASA under your IKEv2 policy); 

Thanks to Daniel Pires from  for helping me figure this out!

I holp it helps you.

 

Sincered,

 

Leonardo Fogaça de Almeida 

 

I forgot,

 

This was the article i used for reference.

 

https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-ipsecikepolicy-rm-powershell

 

Sincered,

 

Leonardo Fogaça de Almeida