HOWTO: Disable DPD keep-alives on ASA

Answered Question
Oct 28th, 2008


I have an IPSec remote access VPN configuration (ASA 7.1 on 1 end - VPN client v 5.0 on the other end) and I have an issue where the connection is dropping regardless if there is traffic been sent across the tunnel or not!!

The tunnel stays up for different periods of time but at the end it dropps!

I have gather the following error message from the ASA:


%PIX|ASA-3-713123: IKE lost contact with remote peer, deleting connection (keepalive type: DPD)

This message indicates that the remote IKE peer did not respond to keep-alives within the expected window of time, so the connection to the IKE peer was terminated.

The message includes the keep-alive mechanism used.

So, Is there a way to disable keep-alives between the VPN Client and the ASA platform ?

What else might resolve this problem

Thanks a lot

I have this problem too.
0 votes
Correct Answer by ajagadee about 7 years 11 months ago


"isakmp keepalive disable" under the Tunnel Group Configuration.



*Pls rate if it helps*

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (2 ratings)
fpellat264 Thu, 11/06/2008 - 01:22

Hi Arul,

I have a similar problem:

My VPN tunnel ended after 3 hours approximatly, I need to increase to 5 hours.

How can I do it?

Kind regards.



This Discussion