cisco FTD and DCD
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-22-2017 07:43 AM - edited 02-21-2020 06:49 AM
I know Cisco ASA support DCD (Dead Connection Detection). Does FTD support this thing ?
Thank you!
- Labels:
-
IPS and IDS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-22-2017 10:32 PM
It does not currently support DCD.
It does support Dead Peer Detection (DPD).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-23-2017 12:07 AM
Dear Marvin,
I think DPD only use for vpn. We have applications go through FTD with long duration session. I need DCD for better control the application, at least we we want function that firewall will sent both side (inside & outside) to reset connection after session timeout. I hope FTD have this function like ASA.
Is FTD just clear connection after session timeout ?
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-23-2017 02:34 AM
Yes - DPD is for VPN.
For session timeout we can modify timeout values via a platform policy as of FTD 6.2.1 and later.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-24-2017 01:11 AM
Thanks for your usefull info, I try to config dcd with flexconfig
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-30-2017 02:06 AM
I have open a TAC case, dcd can config through flexconfig
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2020 04:20 AM - edited 03-01-2020 10:49 AM
I'd like to dig a little deeper into this. DPD might be supported, but I recently set up two VPN tunnels to non-Cisco devices that both were set to restart the tunnels upon DPD failing to receive responses. About 200 seconds in, the tunnels would be reset until we disabled DPD on the remote end. Cisco seems to use opensource charon, which is employed by the StrongSwan, and doesn't seem to work well with DPD. Is it possible that as of 6.5.0 FTD code Cisco has stopped DPD support?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-01-2020 11:18 AM
Hi,
Most probably it's using the legacy keepalive mechanism which is incompatible with DPD. See if flexconfig lets you configure DPD. Otherwise, with DPD, it's good enough to have it configured on one side, failover will still occur, in case you get stucked.
Regards,
Cristian Matei.
