10-19-2005 01:48 AM - edited 03-09-2019 12:45 PM
Hi
Few clarifications needed on DPD
i) Diff btn IKE keepalives and Dead Peer Detection using crypto isakmp keepalive
ii) Say i have an IPSec to a router and i isolate all the interfaces in the router would the keepalives work and bring the IPSec down.
I can kind of guess the answer but would love a clarification.
10-19-2005 03:56 AM
Hi,
i) Keepalive frames are sent at regular intervals regardless of traffic whereas DPD operates during periods of no user traffic.
ii) Yes
HTH
Regards,
Shijo George.
10-19-2005 04:19 AM
Thanx for that. So how (and hence when) do i configure or tweak IKE keepalives and as per your definition what is the difference between Perioidic and on-demand Keepalives. I knew the answer for 2nd was yes cant be anything else. But i dont see any keepalives being generated in my ISAKMP Debug.
Thanx for the reply again
Regds
10-19-2005 05:01 AM
Hi,
When you configure ISAKMP keepalive, the router negotiates the use of either IOS keepalives or DPD whichever the peer device support.
The basic difference between the two is what I said in the earlier post.
Now DPD also can be forced at regular intervals using the periodic command (On Demand is the default behavior for DPD)
Regards,
Shijo George.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide