show crypto isakmp sa - src/dst explanation

Sep 10, 2008 2 Replies

I'm setting a vpn lab and there is one thing I don't really understand from show crypt isakmp sa output.



The HQ router (10.0.0.1) is terminating all vpn connections. However I need a clarification about dst and src columns in the following output.



Why 10.0.0.1 is either in dst or src column? What does it mean?



HQ#show crypto isakmp sa dst src state conn-id slot status



10.0.0.1 192.168.1.1 QM_IDLE 945 0 ACTIVE
10.0.0.1 192.168.2.1 QM_IDLE 1443 0 ACTIVE
192.168.3.1 10.0.0.1 QM_IDLE 701 0 ACTIVE
10.0.0.1 192.168.4.1 QM_IDLE 1435 0 ACTIVE

=A0 =A0conn-id slot status

It depends on the devices who started the VPN session; sometimes

10.0.0.1 sent the first initialization packet, sometimes it didn't.

Just like I suspected. Thanks!

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required