cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
466
Views
0
Helpful
2
Replies

isakmp initiation

yuhuiyao
Level 1
Level 1

When configuring isakmp on routers to set up a ipsec tunnel, which side will initiate the session for udp 500? Or both sides will attempt to initiate the session at the same time?

Thanks,

1 Accepted Solution

Accepted Solutions

mike_guy29
Level 1
Level 1

Hi,

It could be either router that initiates the ISAKMP exchange. It will depend which router sees interesting traffic first. E.g. if you had LAN-A behind Router A, and LAN-B behind Router B and someone from LAN-A tried to ping a machine in LAN-B, Router A would initiate the ISAKMP exchange. Hope that answers your question

Thanks

View solution in original post

2 Replies 2

mike_guy29
Level 1
Level 1

Hi,

It could be either router that initiates the ISAKMP exchange. It will depend which router sees interesting traffic first. E.g. if you had LAN-A behind Router A, and LAN-B behind Router B and someone from LAN-A tried to ping a machine in LAN-B, Router A would initiate the ISAKMP exchange. Hope that answers your question

Thanks

mike_guy29
Level 1
Level 1

Just to clarify on my post, that was under the assumption that we are talking about a LAN to LAN VPN connection as opposed to a Remote Access VPN using a client etc.

Thanks