09-28-2010 09:39 PM
Dear All,
I have some question about some error from ASA 5500?
some time i saw Role: Responder and some time i saw Role: initiator
what does it mean ?
and what is the problem ?
HQ# sh crypto isakmp sa
Active SA: 3
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 3
1 IKE Peer: 10.189.137.8
Type : L2L Role : responder
Rekey : no State : MM_ACTIVE
2 IKE Peer: 10.189.137.10
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
3 IKE Peer: 10.189.137.9
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
HQ#
Solved! Go to Solution.
09-28-2010 09:45 PM
Responder means that the peer initiated the VPN connection while Initiator means that the VPN tunnel is initiated from this end.
Hope that answers your question.
09-28-2010 10:07 PM
MM_Active means that phase 1 is coming up OK - it's working fine.
The role of responder or initiator just means which device initiates the VPN tunnel. Whether your ASA is the one who initiates the VPN tunnel, or the remote peer initiates the VPN tunnel.
To identify whether phase 1 is working fine or not is the State: MM_ACTIVE. If the state is others, for example: MM_WAIT_MSG2, that means VPN is not working as it is waiting for Message#2.
09-28-2010 09:45 PM
Responder means that the peer initiated the VPN connection while Initiator means that the VPN tunnel is initiated from this end.
Hope that answers your question.
09-28-2010 09:49 PM
Dear jennifer,
sorry i'm still not clear about this!!!
Role : responder it mean it working properly right?
Role : initiator it mean it not workin properly right?
please help me more detail on this!!!!!
Thanks
09-28-2010 10:07 PM
MM_Active means that phase 1 is coming up OK - it's working fine.
The role of responder or initiator just means which device initiates the VPN tunnel. Whether your ASA is the one who initiates the VPN tunnel, or the remote peer initiates the VPN tunnel.
To identify whether phase 1 is working fine or not is the State: MM_ACTIVE. If the state is others, for example: MM_WAIT_MSG2, that means VPN is not working as it is waiting for Message#2.
09-29-2010 12:05 AM
Dear Jennifer,
Thanks for your help!!!
I will rate to you !!!
i close this question and i will create other question about VPN site to site ( HQ share internet to Branch)!!!
I Hope you can help me !!!
Bes Regards,
02-06-2018 10:37 PM
Good Explanation ....
05-18-2019 01:17 AM
:0)
08-22-2019 03:54 AM
can you explain how to change Role from responder to initiator ?
08-22-2019 03:55 AM
can you explain how to change Role from responder to initiator ?
08-22-2019 09:58 AM
Hi
it's made automatically as soon as one peer of the tunnel to come up has a traffic for the remote encryption domain.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide