ā11-22-2017 07:43 AM - edited ā02-21-2020 06:49 AM
I know Cisco ASA support DCD (Dead Connection Detection). Does FTD support this thing ?
Thank you!
ā11-22-2017 10:32 PM
It does not currently support DCD.
It does support Dead Peer Detection (DPD).
ā11-23-2017 12:07 AM
Dear Marvin,
I think DPD only use for vpn. We have applications go through FTD with long duration session. I need DCD for better control the application, at least we we want function that firewall will sent both side (inside & outside) to reset connection after session timeout. I hope FTD have this function like ASA.
Is FTD just clear connection after session timeout ?
Thank you.
ā11-23-2017 02:34 AM
Yes - DPD is for VPN.
For session timeout we can modify timeout values via a platform policy as of FTD 6.2.1 and later.
ā11-24-2017 01:11 AM
Thanks for your usefull info, I try to config dcd with flexconfig
ā11-30-2017 02:06 AM
I have open a TAC case, dcd can config through flexconfig
ā02-27-2020 04:20 AM - edited ā03-01-2020 10:49 AM
I'd like to dig a little deeper into this. DPD might be supported, but I recently set up two VPN tunnels to non-Cisco devices that both were set to restart the tunnels upon DPD failing to receive responses. About 200 seconds in, the tunnels would be reset until we disabled DPD on the remote end. Cisco seems to use opensource charon, which is employed by the StrongSwan, and doesn't seem to work well with DPD. Is it possible that as of 6.5.0 FTD code Cisco has stopped DPD support?
ā03-01-2020 11:18 AM
Hi,
Most probably it's using the legacy keepalive mechanism which is incompatible with DPD. See if flexconfig lets you configure DPD. Otherwise, with DPD, it's good enough to have it configured on one side, failover will still occur, in case you get stucked.
Regards,
Cristian Matei.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide