Few clarifications needed on DPD
i) Diff btn IKE keepalives and Dead Peer Detection using crypto isakmp keepalive
ii) Say i have an IPSec to a router and i isolate all the interfaces in the router would the keepalives work and bring the IPSec down.
I can kind of guess the answer but would love a clarification.
Thanx for that. So how (and hence when) do i configure or tweak IKE keepalives and as per your definition what is the difference between Perioidic and on-demand Keepalives. I knew the answer for 2nd was yes cant be anything else. But i dont see any keepalives being generated in my ISAKMP Debug.
Thanx for the reply again
When you configure ISAKMP keepalive, the router negotiates the use of either IOS keepalives or DPD whichever the peer device support.
The basic difference between the two is what I said in the earlier post.
Now DPD also can be forced at regular intervals using the periodic command (On Demand is the default behavior for DPD)