cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
571
Views
0
Helpful
1
Replies

ASA dead-peer-detection behaviour

binelipetrov
Level 1
Level 1

ASA is by default sending DPD R_U_THERE packets and expecting R_U_THERE_ACK packets from peer.

My question is: in which moment ASA is sending DPD packets? Is this "always on" behavior or ASA is starting sending DPD packets once it stops receiving encrypted traffic over the tunnel from the peer? In this case, what is the idleness period or idleness criteria?

Thanks

1 Reply 1

Ivan Martinon
Level 7
Level 7

DPD's are sent only when there is no traffic flowing through the tunnel, the values are defined under the tunnel group that affects this lan to lan/remote access

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i3.html#wp1842584

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card