cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1150
Views
0
Helpful
2
Replies

Using dead peer detection(DPD) on Cisco router

eagle.leung
Level 1
Level 1

Does anyone try to configure DPD without problem??

Is that the remote peer need to support the same feature and needs to enable it????

I have open the debug command but nothing to see regarding the DPD message on the DPD enabled router.

Please advise the problem!!

2 Replies 2

ehirsel
Level 6
Level 6

This link may be of use in configuring DPD.

http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/products_feature_guide09186a00801ee19a.html

According to the link, both ends need to enable the same protocol.

Note that the isakmp keepalive is not the same as DPD, but if your router's IOS image can perform both, then configure both - which protocol will be used depends upon which protocol the remote peer supports.

Let me know if you need more help.

Because the remote peer does not support DPD, I just wonder can I get any hello message on the DPD enabled router using the debug crypto isakmp. According to the link, as least there have some request and response meesage by the debug command.

I have try to use keepalive (not DPD)on both router, I can't verify whether the feature is working or not without the hello message display by the debug command.

In addition, does there any feature that the Cisco can be auto bring up the VPN tunnel without trigger the interest traffic, that means the VPN tunnel is always up. I know that the EZVPN can be done that. But how about standard IPsec ?? From my point of view, I just try DPD to see whether can be done for this issue.

Please try to help me!!

Thanks in advance for your information