Skip to main content
fjulianom
Explorer II
May 29, 2018
Question

About DPD

  • May 29, 2018
  • 4 replies
  • 14010 views

Hi guys,

 

I have implemented a VPN in my FortiGate and is up and working, but I don't know if my DPD configuration is correct or not. First of all I would like to know what is the main purpose of DPD, I understand it send packets over the VPN to check if the peer is up or not? But what happens when the peer is down? What does DPD do to solve the problem? Or what does DPD just do? On the other hand, there are two modes when it is enabled, "on idle" and "on demand", what is the difference between the two? I have read the documentation but is not clear.

 

Regards,

Julián 

    4 replies

    emnoc
    New Member
    May 29, 2018

    1st DPD comes into play when no traffic is sent over the IPSEC peer and at phase1

     

    This ensure stale ipsec/ike peers are cleared

    enable means we  exclusively enable it regardless if it's negotiated by the party

     

    on-demand means when a peer during the IKE exchange between Int/Responder  that offers DPD, and then only than will the FGT use DPD

     

     

     

    fjulianom
    fjulianomAuthor
    Explorer II
    May 29, 2018

    Hi emnoc,

     

    And "on idle"?

     

    Regards,

    Julián

    emnoc
    New Member
    May 29, 2018

    On IDLE is when DPD takes places, if this  dialup vpn than most likely NAT-T  keepAlives are being used enlew of DPD. Keep in mind DPD is for when "IPSEC SAs are  idle ", ( no need for  DPD  &  if traffic is passing both ways at  IPSEC payload )

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.