<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Debugging Dead Peer Detection (dpd) on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/debugging-dead-peer-detection-dpd-on-asa/m-p/688257#M1027883</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found answer to one of my questions, debug crypto isakmp 7 will display dpd messages. It also looks like the pix retries 4 times before peer is considered down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is, my tunnel between asa and pix is flapping every so often for no apparent reason. It usually comes right back up after it is torn down. From this log in pix it appears asa is not replying to dpd r u there request from pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_FAIL&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DELETE_ALL_SPIS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I increase idle time for dpd messages? I do need the pix at remote end to failover to second asa peer if main asa connection fails. I assume making the idle time longer would also make that failover process take longer. &lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did this post get rated 5.0 by myself???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Jan 2007 20:02:39 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-01-26T20:02:39Z</dc:date>
    <item>
      <title>Debugging Dead Peer Detection (dpd) on ASA</title>
      <link>https://community.cisco.com/t5/network-security/debugging-dead-peer-detection-dpd-on-asa/m-p/688256#M1027882</link>
      <description>&lt;P&gt;Is there a similar command for ASA like "isakmp log #" in a pix? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, from what I have read about dpd in asa, you can specify the idle value in seconds, which specifies how long tunnel can be idle before dpd starts, as well as a retry value in seconds which is the number of seconds between retries. The question is, can you configure how many retries can fail before the peer is considered to be down? If not, what is the default? Is it 1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/debugging-dead-peer-detection-dpd-on-asa/m-p/688256#M1027882</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2019-03-11T09:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Debugging Dead Peer Detection (dpd) on ASA</title>
      <link>https://community.cisco.com/t5/network-security/debugging-dead-peer-detection-dpd-on-asa/m-p/688257#M1027883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found answer to one of my questions, debug crypto isakmp 7 will display dpd messages. It also looks like the pix retries 4 times before peer is considered down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is, my tunnel between asa and pix is flapping every so often for no apparent reason. It usually comes right back up after it is torn down. From this log in pix it appears asa is not replying to dpd r u there request from pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_TX&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DPD_FAIL&lt;/P&gt;&lt;P&gt;peer 1.1.1.1 , DELETE_ALL_SPIS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I increase idle time for dpd messages? I do need the pix at remote end to failover to second asa peer if main asa connection fails. I assume making the idle time longer would also make that failover process take longer. &lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did this post get rated 5.0 by myself???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2007 20:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/debugging-dead-peer-detection-dpd-on-asa/m-p/688257#M1027883</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-26T20:02:39Z</dc:date>
    </item>
  </channel>
</rss>

