Confirm IPsec roles using CLI


In IPsec each endpoint can be an initiator or a responder. If your IPsec tunnel is configured to accept connections from any IP address, then it is a responder. Otherwise it is an initiator. This detail may be useful when troubleshooting IPsec tunnel issues. 

If you do not have UI access and you wish to determine the IPsec role using CLI, you can run the following command to download and execute a script to show the role for each tunnel.

For NG Firewall

curl -k | python3

For Micro Edge

curl -k | python3
