cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
775
Views
5
Helpful
5
Replies

Quick Question on isakmp keepalive

jonathanstevens
Level 1
Level 1

What exactly does the isakmp keepalive do?

What packets are sent? What function does it run?

5 Replies 5

jmia
Level 7
Level 7

Jonathan,

The crypto isakmp keepalive command is used to send IKE keepalives, which detect the continued connectivity of an IKE security association (SA), between two peer points.

Hope this helps a little,

Jay

I assume they would be UDP packets (port 500)?

To what degree do they check the connection?

Is it a "HELLO" "HELLO I got your HELLO" type thing, or is it more complex?

Jonathan,

You'll find the answers to your questions here (RFC 3706) : http://www.faqs.org/rfcs/rfc3706.html

DPD (Dead Peer Detection) is used to asertain if the remote peer is alive or not, all explained in the RFC - enjoy the read.

Hope this helps.

Jay

I am having a problem with an a tunnel establishing and staying alive. The Cisco TAC rep suggested the problem might be similar to bug CSCdw64626 and that setting the crypto isakmp keepalive to a more aggressive value could solve the problem.

Any idea what an aggressive setting would be?

Thanks,

Rob

Jay - Thanks. Exactly what I was looking for.

Rob - Try 10 seconds.