Cisco/PIX/ASA ISAKMP States
Details on the various connection states shown in the output from commands show isakmp sa or show crypto isakmp sa executed on a Cisco PIX or ASA firewall appliance.
MM_SA_SETUP
Policy parameters have been successfully negotiated
MM_NO_STATE
Phase 1 has failed, policy parameters have not been successfully negotiated.
- Check there is a matching crypto policy configured on both peers
- Check you have applied and activated the relevant crypto map/policy on both peers, on the correct interface
AG_NO_STATE
As above but displayed for agressive mode connections
MM_KEY_EXCH
Peers are authenticating. If phase 1 fails here, authentication of a peer device has failed
- Check the pre-shared key matches at both ends
- Check the time on each peer is reasonably close to the others
- If using certificates, confirm they are valid and have not been revoked
AG_INIT_EXCH
As above but displayed for agressive mode connections
MM_KEY_AUTH
Authentication of the peer devices has been successful, expect the state to transition to QM_IDLE or MM_ACTIVE shortly
AG_AUTH
As above but displayed for agressive mode connections
QM_IDLE
Phase 1 completed successfully