The DPD is "not persistent" and is only triggered by a Phase 2 rekey

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

The DPD is "not persistent" and is only triggered by a Phase 2 rekey

Cyber Elite
Cyber Elite

 

I was reading this KB article about DPD

 

 

does this mean that say when phase 1 is down or its lifetime expires will DPD will come into play?

 

or 

 

when when phase 1 is red and phase 2 about to expire rekey will happen for phase 2 then DPD will come into play?

MP

Help the community: Like helpful comments and mark solutions.
2 accepted solutions

Accepted Solutions

this means the remote end was not able to respond to the R-U-THERE packet

 

this is like a heartbeat but with a little more 'intelligence': a ping heartbeat may be replied to by a system that is in a crashed state, while a isakmp r-u-there requires the host to lookup it's SA and formulate a reply. if DPD determines the remote end did not reply, the remote peer is identified as down

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

If phase 1 is up and you get a DPD error, phase 1 will not stay up for long anymore as there is an SA mismatch or the remote peer is down
If the remote end stops sending DPD heartbeats, it has likely torn down the tunnel, or has died
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

7 REPLIES 7

Cyber Elite
Cyber Elite

hi @MP18 

Which article exactly?

 

please read this one: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK

 

DPD is used to detect if the peer device still has a valid IKE-SA. Periodically, it will send a “ISAKMP R-U-THERE” packet to the peer, which will respond back with an “ISAKMP R-U-THERE-ACK” acknowledgement.

 

so to both your questions: no

DPD is used to check on a healthy tunnel from the moment it is established

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

On system log i see if i filter via

 

( subtype eq vpn ) and ( severity eq low)

 

description contains 'IKE phase-1 SA is down determined by DPD.' ) and ( eventid eq ike-nego-p1-dpd-dn )

 

Does this mean that if phase 1 is down DPD will inform us?

 

Curious to understand this log?

MP

Help the community: Like helpful comments and mark solutions.

this means the remote end was not able to respond to the R-U-THERE packet

 

this is like a heartbeat but with a little more 'intelligence': a ping heartbeat may be replied to by a system that is in a crashed state, while a isakmp r-u-there requires the host to lookup it's SA and formulate a reply. if DPD determines the remote end did not reply, the remote peer is identified as down

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

so does this mean that even if phase 1 is up and for some reason it is normail to see this message?

 

when we do not get DPD ask from neighbour device can we assume that phase 1 is down?

MP

Help the community: Like helpful comments and mark solutions.

Please answer my last question

MP

Help the community: Like helpful comments and mark solutions.

If phase 1 is up and you get a DPD error, phase 1 will not stay up for long anymore as there is an SA mismatch or the remote peer is down
If the remote end stops sending DPD heartbeats, it has likely torn down the tunnel, or has died
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Many Thanks Reaper

MP

Help the community: Like helpful comments and mark solutions.
  • 2 accepted solutions
  • 8457 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!