<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The DPD is &amp;quot;not persistent&amp;quot; and is only triggered by a Phase 2 rekey in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260221#M73764</link>
    <description>&lt;P&gt;this means the remote end was not able to respond to the R-U-THERE packet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is like a heartbeat but with a little more 'intelligence': a ping heartbeat may be replied to by a system that is in a crashed state, while a isakmp r-u-there requires the host to lookup it's SA and formulate a reply. if DPD determines the remote end did not reply, the remote peer is identified as down&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2019 07:49:17 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-05-08T07:49:17Z</dc:date>
    <item>
      <title>The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/259864#M73650</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was reading this KB article about DPD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does this mean that say when phase 1 is down or its lifetime expires will DPD will come into play?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when when phase 1 is red and phase 2 about to expire rekey will happen for phase 2 then DPD will come into play?&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 16:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/259864#M73650</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-04T16:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260084#M73714</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which article exactly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please read this one:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;DPD is used to detect if the peer device still has a valid IKE-SA. Periodically, it will send a “ISAKMP R-U-THERE” packet to the peer, which will respond back with an “ISAKMP R-U-THERE-ACK” acknowledgement.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so to both your questions: no&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;DPD is used to check on a healthy tunnel from the moment it is established&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 08:09:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260084#M73714</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-07T08:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260210#M73755</link>
      <description>&lt;P&gt;On system log i see if i filter via&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;( subtype eq vpn ) and ( severity eq low)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;description contains 'IKE phase-1 SA is down determined by DPD.' ) and ( eventid eq ike-nego-p1-dpd-dn )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this mean that if phase 1 is down DPD will inform us?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Curious to understand this log?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 03:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260210#M73755</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-08T03:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260221#M73764</link>
      <description>&lt;P&gt;this means the remote end was not able to respond to the R-U-THERE packet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is like a heartbeat but with a little more 'intelligence': a ping heartbeat may be replied to by a system that is in a crashed state, while a isakmp r-u-there requires the host to lookup it's SA and formulate a reply. if DPD determines the remote end did not reply, the remote peer is identified as down&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 07:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260221#M73764</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-08T07:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260322#M73789</link>
      <description>&lt;P&gt;so does this mean that even if phase 1 is up and for some reason it is normail to see this message?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when we do not get DPD ask from neighbour device can we assume that phase 1 is down?&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 05:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260322#M73789</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-09T05:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260530#M73854</link>
      <description>&lt;P&gt;Please answer my last question&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 16:40:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260530#M73854</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-10T16:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260591#M73863</link>
      <description>If phase 1 is up and you get a DPD error, phase 1 will not stay up for long anymore as there is an SA mismatch or the remote peer is down&lt;BR /&gt;If the remote end stops sending DPD heartbeats, it has likely torn down the tunnel, or has died</description>
      <pubDate>Fri, 10 May 2019 22:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260591#M73863</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-10T22:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: The DPD is "not persistent" and is only triggered by a Phase 2 rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260603#M73866</link>
      <description>&lt;P&gt;Many Thanks Reaper&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2019 05:29:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-dpd-is-quot-not-persistent-quot-and-is-only-triggered-by-a/m-p/260603#M73866</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-11T05:29:48Z</dc:date>
    </item>
  </channel>
</rss>

