Cisco/PIX/ASA ISAKMP States

Details on the various connection states shown in the output from commands show isakmp sa or show crypto isakmp sa executed on a Cisco PIX or ASA firewall appliance.

MM_SA_SETUP

Policy parameters have been successfully negotiated

MM_NO_STATE

Phase 1 has failed, policy parameters have not been successfully negotiated.

  • Check there is a matching crypto policy configured on both peers
  • Check you have applied and activated the relevant crypto map/policy on both peers, on the correct interface

AG_NO_STATE

As above but displayed for agressive mode connections

MM_KEY_EXCH

Peers are authenticating. If phase 1 fails here, authentication of a peer device has failed

  • Check the pre-shared key matches at both ends
  • Check the time on each peer is reasonably close to the others
  • If using certificates, confirm they are valid and have not been revoked

AG_INIT_EXCH

As above but displayed for agressive mode connections

MM_KEY_AUTH

Authentication of the peer devices has been successful, expect the state to transition to QM_IDLE or MM_ACTIVE shortly

AG_AUTH

As above but displayed for agressive mode connections

QM_IDLE

Phase 1 completed successfully