08-24-2015 03:49 PM
08-25-2015 12:34 AM
Hello stownsend,
isakmp keepalive threshold infinite
This configures "one-way" DPD mode on ASA. The ASA will respond to R-U-THERE messages, but will not initiate DPD exchange.
isakmp keepalive disable
This will completely disable DPD on ASA and it will not negotiate it with a peer.
Source:-
DPD : https://supportforums.cisco.com/document/32546/dead-peer-detection
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
08-25-2015 07:45 AM
I had set isakmp keepalive threshold infinite on both the head end and the remote, so that would seem like that would be the same as isakmp keepalive disable on either end?
I'm asking because I've tried the isakmp keepalive threshold infinite command and that didn't work well at all. I've been asked to use the isakmp keepalive disable command. If it is going to do the same thing I don't want to risk taking down the remote site again.
Thank you,
08-25-2015 07:02 PM
Setting isakmp to "infinite" on both sides is equivalent to disabling them as both sides will not initiate DPDs but will expect other side to send DPDs which is not going to occur eventually.
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide