Symptom
This is enhancement to force UDP encapsulation for ESP packets from the responder side of the IKEv2 tunnel.
Conditions
No NAT between IKEv2 VPN peers and UDP encapsulation is needed - e.g. due to ISP blocking ESP (protocol 50).
Workaround
Force UDP encapsulation on the initiator:
crypto ikev2 profile
nat force-encap
Initiator needs to run IOS-XE 16.9.1 or newer or IOS 15.7(03)M02 or newer.
Further Problem Description