@MP18 wrote:
why my PA is responder for Phase 1 and Initator for Phase 2?
Why not? 😛
- How many proxy IDs do you have configured on that tunnel?
- What timeouts do you have configured for phase 1 and 2?
For example if you have only 1 phase 2 tunnel and a timeout of 8 hours in phase 1 and 1 hour for phase 2. At 2 am the other side establishes a connection so phase 1 and 2 will be setup. At that time your PA is responder for phase 1 and 2. After exchanging some packets there is no longer a connection so phase 2 will time out. For example at 4 am your side wants to connect to the remote network. As phase 2 already timed out a new one needs to be created but phase 1 is still up. --> your PA is responder in phase 1 and initiator of phase 2