- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-04-2019 09:34 AM
I was reading this KB article about DPD
does this mean that say when phase 1 is down or its lifetime expires will DPD will come into play?
or
when when phase 1 is red and phase 2 about to expire rekey will happen for phase 2 then DPD will come into play?
05-08-2019 12:49 AM
this means the remote end was not able to respond to the R-U-THERE packet
this is like a heartbeat but with a little more 'intelligence': a ping heartbeat may be replied to by a system that is in a crashed state, while a isakmp r-u-there requires the host to lookup it's SA and formulate a reply. if DPD determines the remote end did not reply, the remote peer is identified as down
05-10-2019 03:09 PM
05-07-2019 01:09 AM
hi @MP18
Which article exactly?
please read this one: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK
DPD is used to detect if the peer device still has a valid IKE-SA. Periodically, it will send a “ISAKMP R-U-THERE” packet to the peer, which will respond back with an “ISAKMP R-U-THERE-ACK” acknowledgement.
so to both your questions: no
DPD is used to check on a healthy tunnel from the moment it is established
05-07-2019 08:13 PM
On system log i see if i filter via
( subtype eq vpn ) and ( severity eq low)
description contains 'IKE phase-1 SA is down determined by DPD.' ) and ( eventid eq ike-nego-p1-dpd-dn )
Does this mean that if phase 1 is down DPD will inform us?
Curious to understand this log?
05-08-2019 12:49 AM
this means the remote end was not able to respond to the R-U-THERE packet
this is like a heartbeat but with a little more 'intelligence': a ping heartbeat may be replied to by a system that is in a crashed state, while a isakmp r-u-there requires the host to lookup it's SA and formulate a reply. if DPD determines the remote end did not reply, the remote peer is identified as down
05-08-2019 10:24 PM
so does this mean that even if phase 1 is up and for some reason it is normail to see this message?
when we do not get DPD ask from neighbour device can we assume that phase 1 is down?
05-10-2019 09:40 AM
Please answer my last question
05-10-2019 03:09 PM
05-10-2019 10:29 PM
Many Thanks Reaper
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!