ā07-27-2017 03:04 AM - edited ā03-12-2019 06:16 PM
Hi,
please share me the command to check Dead Connection Detection is enabled or not in ASA firewall.
sankar
ā07-27-2017 03:16 AM
Hi Sankar,
You need to check the output of show service-policy from the ASA to see of DCD is in effect.
More info:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/conns_connlimits.html#wp1080752
Regards,
Aditya
Please rate helpful and mark correct answers
ā07-27-2017 03:24 AM
Hi Suresh,
Thanks for the quick reply.
actually, i got a mail from my client.
" would you ask your network guys to check the DCD (Dead Connection Detection) config on your firewall at the DC end of the VPN Tunnel - e.g. has DCD been enabled, and if so what is the setting
".
which output should I give to my client?
sankar
ā07-27-2017 03:33 AM
Hi Sankar,
My name is Aditya :)
To check this you would need to go the tunnel group config of the VPN peer.
sh run all tunnel-group <IP>
Check the
Regards,
Aditya
Please rate helpful and mark correct answers
ā07-27-2017 04:03 AM
Hi Aditya,
Thanks for your quick replies.
Actually, we have a VPN Tunnel between our DC and the client location. previously everything working fine. 20days back my client has changed their firewall. Then onwards we are facing some packet loss issue and sometimes we are able to telnet their
Now, he is asking about Dead Connection Detection is enabled or not, if it enabled what is the setting you did in your firewall.
If it's a VPN-Tunnel then it's a Dead Peer Detection right. but my client is asking about Dead Connection Detection. I am confused to reply my client mail.
so I am thinking to share both DCD and DPD settings to my client.
can you please suggest me what is the correct reply to my client.
Thanks,
sankar
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide