cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
957
Views
0
Helpful
0
Replies

DPD Adjustment Suggestions - SSL/DTLS Clients

estein
Level 1
Level 1

We have 5580s and 5550s, all on 8.4(2) and configured to allow AnyConnect SSL clients to connect using DTLS.  We have enough users complaining of frequent dropped VPN connections, and see enough disconnections in our syslogs, to be concerned.  All of the users who complain of instability are on a "traditional" WLAN, or are using a wifi hotspot through a mobile phone, or are using a cellular data card connection. 

We're investigating different ways to improve stability, and one is possibly adjusting the DPD timers.  We're thinking this could make the VPN connection more forgiving when it comes to an internet blip (that is more likely when on a wireless connection of some type).

Current DPD settings are:

30 seconds for Gateway Side Detection, and

30 seconds for Client Side Detection.

We plan to do some testing where we bump up the timers on a test ASA and have 'problem users' connect to see if they experience improvements.

Anyone run into similar problems, and make similar adjustments?  Any recommendations based on your experiences? 

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: