cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
379
Views
4
Helpful
3
Replies

DPDs

attrgautam
Level 5
Level 5

Hi

Few clarifications needed on DPD

i) Diff btn IKE keepalives and Dead Peer Detection using crypto isakmp keepalive

ii) Say i have an IPSec to a router and i isolate all the interfaces in the router would the keepalives work and bring the IPSec down.

I can kind of guess the answer but would love a clarification.

3 Replies 3

shijogeorge
Level 1
Level 1

Hi,

i) Keepalive frames are sent at regular intervals regardless of traffic whereas DPD operates during periods of no user traffic.

ii) Yes

HTH

Regards,

Shijo George.

Thanx for that. So how (and hence when) do i configure or tweak IKE keepalives and as per your definition what is the difference between Perioidic and on-demand Keepalives. I knew the answer for 2nd was yes cant be anything else. But i dont see any keepalives being generated in my ISAKMP Debug.

Thanx for the reply again

Regds

Hi,

When you configure ISAKMP keepalive, the router negotiates the use of either IOS keepalives or DPD whichever the peer device support.

The basic difference between the two is what I said in the earlier post.

Now DPD also can be forced at regular intervals using the periodic command (On Demand is the default behavior for DPD)

Regards,

Shijo George.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: