Symptoms
This problem occurs when you configure the following:
-
You use Routing and Remote Access Service (RRAS) to set up Internet Key Exchange version 2 (IKEv2) protocol-based site-to-site tunnels for cross-premises network connection in Windows Server 2012 R2.
-
You have UDP port 4500 blocked.
Cause
This problem occurs because UDP port 4500 is required even though Mobility and Multihoming Protocol (MOBIKE) and NAT traversal (NAT-T) are disabled.
Note UDP port 4500 is just used by MOBIKE and NAT-T. Therefore, UDP port 4500 should not be involved in IPsec site-to-site VPN connections.Resolution
To resolve this problem, install the December 2014 update rollup for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2.
Status
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
More Information
See the terminology that Microsoft uses to describe software updates.