Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fjulianom
New Contributor III

About DPD

Hi guys,

 

I have implemented a VPN in my FortiGate and is up and working, but I don't know if my DPD configuration is correct or not. First of all I would like to know what is the main purpose of DPD, I understand it send packets over the VPN to check if the peer is up or not? But what happens when the peer is down? What does DPD do to solve the problem? Or what does DPD just do? On the other hand, there are two modes when it is enabled, "on idle" and "on demand", what is the difference between the two? I have read the documentation but is not clear.

 

Regards,

Julián 

4 REPLIES 4
emnoc
Esteemed Contributor III

1st DPD comes into play when no traffic is sent over the IPSEC peer and at phase1

 

This ensure stale ipsec/ike peers are cleared

enable means we  exclusively enable it regardless if it's negotiated by the party

 

on-demand means when a peer during the IKE exchange between Int/Responder  that offers DPD, and then only than will the FGT use DPD

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
fjulianom
New Contributor III

Hi emnoc,

 

And "on idle"?

 

Regards,

Julián

emnoc
Esteemed Contributor III

On IDLE is when DPD takes places, if this  dialup vpn than most likely NAT-T  keepAlives are being used enlew of DPD. Keep in mind DPD is for when "IPSEC SAs are  idle ", ( no need for  DPD  &  if traffic is passing both ways at  IPSEC payload )

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
fjulianom
New Contributor III

Hi,

 

I've read DPD on the FortiOS™ Handbook which gives an overview of it. It also explains the "on-demand" option:

 

 

Regards,

Julián

Labels
Top Kudoed Authors