For every VPN tunnel there is an Initiator device triggering the IKE negotiation and the Responder device accepting the first IKE exchange packets. Understanding the roles is helpful when troubleshooting VPN issues.
Identify the role with ' show security ike security-associations ' as shown below:
show security ike security-associations
root@Corporate> show security ike security-associations Index State Initiator cookie Responder cookie Mode Remote Address 6695410 UP 4f61f68dcad7bd87 e3a72e5385d72fcc Main 192.168.1.1 root@Corporate> ...ity-associations index 6695410 detail IKE peer 192.168.1.1, Index 6695410, Gateway Name: Gateway Role: Initiator, State: UP ==> Here Initiator cookie: 4f61f68dcad7bd87, Responder cookie: e3a72e5385d72fcc