isakmp initiation

Answered Question
Dec 11th, 2008

When configuring isakmp on routers to set up a ipsec tunnel, which side will initiate the session for udp 500? Or both sides will attempt to initiate the session at the same time?

Thanks,

Correct Answer by mike_guy29 about 8 years 2 months ago

Hi,

It could be either router that initiates the ISAKMP exchange. It will depend which router sees interesting traffic first. E.g. if you had LAN-A behind Router A, and LAN-B behind Router B and someone from LAN-A tried to ping a machine in LAN-B, Router A would initiate the ISAKMP exchange. Hope that answers your question

Thanks

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
mike_guy29 Thu, 12/11/2008 - 14:06

Hi,

It could be either router that initiates the ISAKMP exchange. It will depend which router sees interesting traffic first. E.g. if you had LAN-A behind Router A, and LAN-B behind Router B and someone from LAN-A tried to ping a machine in LAN-B, Router A would initiate the ISAKMP exchange. Hope that answers your question

Thanks

mike_guy29 Thu, 12/11/2008 - 14:08

Just to clarify on my post, that was under the assumption that we are talking about a LAN to LAN VPN connection as opposed to a Remote Access VPN using a client etc.

Thanks

Actions

This Discussion