When configuring isakmp on routers to set up a ipsec tunnel, which side will initiate the session for udp 500? Or both sides will attempt to initiate the session at the same time?
It could be either router that initiates the ISAKMP exchange. It will depend which router sees interesting traffic first. E.g. if you had LAN-A behind Router A, and LAN-B behind Router B and someone from LAN-A tried to ping a machine in LAN-B, Router A would initiate the ISAKMP exchange. Hope that answers your question