<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Sankar, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095599#M133716</link>
    <description>&lt;P&gt;Hi Sankar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to check the output of show service-policy from the ASA to see of DCD is in effect.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;More info:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/conns_connlimits.html#wp1080752&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2017 10:16:54 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2017-07-27T10:16:54Z</dc:date>
    <item>
      <title>How to check Dead connection Detection is enabled or not in asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095598#M133715</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;please share me the command to check Dead Connection Detection is enabled or not in ASA firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;G class="gr_ gr_174 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="174" data-gr-id="174"&gt;Thnaks&lt;/G&gt;&lt;BR /&gt;sankar&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095598#M133715</guid>
      <dc:creator>sankar.ramoju</dc:creator>
      <dc:date>2019-03-13T01:16:06Z</dc:date>
    </item>
    <item>
      <title>Hi Sankar,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095599#M133716</link>
      <description>&lt;P&gt;Hi Sankar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to check the output of show service-policy from the ASA to see of DCD is in effect.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;More info:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/conns_connlimits.html#wp1080752&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 10:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095599#M133716</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-07-27T10:16:54Z</dc:date>
    </item>
    <item>
      <title>Hi Suresh,Thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095600#M133717</link>
      <description>&lt;P&gt;Hi Suresh,&lt;BR /&gt;&lt;BR /&gt;Thanks for the quick reply.&lt;BR /&gt;&lt;BR /&gt;actually, i got a mail from my client.&lt;/P&gt;
&lt;P&gt;" would you ask your network guys to check the DCD (Dead Connection Detection) config on your firewall at the DC end of the VPN Tunnel - e.g. has DCD been enabled, and if so what is the setting&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;".&lt;BR /&gt;&lt;BR /&gt;which output should I give to my client?&lt;BR /&gt;&lt;BR /&gt;&lt;G class="gr_ gr_210 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="210" data-gr-id="210"&gt;Thnaks&lt;/G&gt;,&lt;BR /&gt;sankar&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 10:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095600#M133717</guid>
      <dc:creator>sankar.ramoju</dc:creator>
      <dc:date>2017-07-27T10:24:55Z</dc:date>
    </item>
    <item>
      <title>Hi Sankar,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095601#M133718</link>
      <description>&lt;P&gt;Hi Sankar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My name is Aditya &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;To check this you would need to go the tunnel group config of the VPN peer.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh run all tunnel-group &amp;lt;IP&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check the &lt;G class="gr_ gr_146 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="146" data-gr-id="146"&gt;ipsec&lt;/G&gt;-attributes and it will show you the keepalive (DPD) values.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 10:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095601#M133718</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-07-27T10:33:52Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095602#M133719</link>
      <description>&lt;P&gt;Hi Aditya,&lt;BR /&gt;&lt;BR /&gt;Thanks for your quick replies.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Actually, we have a VPN Tunnel between our DC and the client location. previously everything working fine. 20days back my client has changed their firewall. Then onwards we are facing some packet loss issue and sometimes we are able to telnet their&amp;nbsp;&lt;G class="gr_ gr_303 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del" id="303" data-gr-id="303"&gt;ips&lt;/G&gt; and some times not able connect to their &lt;G class="gr_ gr_465 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del" id="465" data-gr-id="465"&gt;ips&lt;/G&gt; through vpn tunnel. In &lt;G class="gr_ gr_920 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del" id="920" data-gr-id="920"&gt;asa&lt;/G&gt;&amp;nbsp;logs, I have&amp;nbsp;observed syn timeout problem. but the client is saying everything fine at their end, they suspected some problem with my DC firewall configuration.&lt;/P&gt;
&lt;P&gt;Now,&amp;nbsp;he is asking about Dead Connection Detection is enabled or not, if it enabled what is the setting you did in your firewall.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If it's a VPN-Tunnel then it's a Dead Peer Detection right. but my client is asking about Dead Connection Detection. I am confused to reply my client mail.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so I am thinking to share both DCD and DPD settings to my client.&lt;BR /&gt;&lt;BR /&gt;can you please suggest me what is the correct reply to my client.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;sankar&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 11:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-check-dead-connection-detection-is-enabled-or-not-in-asa/m-p/3095602#M133719</guid>
      <dc:creator>sankar.ramoju</dc:creator>
      <dc:date>2017-07-27T11:03:47Z</dc:date>
    </item>
  </channel>
</rss>

