IKE_SA_INIT 'Initiator Request' uses random source port
search cancel

IKE_SA_INIT 'Initiator Request' uses random source port

book

Article ID: 383778

calendar_today

Updated On:

Products

VMware VeloCloud SD-WAN

Issue/Introduction

IKE_SA_INIT 'Initiator Request' uses random source port instead of UDP port 500 for Non-SDWAN connections.

Environment

VMware SDWAN, Velocloud SDWAN, Non SDWAN Destination

Cause

Velocloud SDWAN software security module was initiating IKE session with source port as 500 till software version 5.0.x.x.

From 5.1.0.0 the enhanced security module is taking random source port for IKE sessions.

In 5.1.x.x onwards, we can not force to send all  IKE_SA_INIT packets with source port as 500.

Resolution

This behavior is expected.