Hi guys,
I have implemented a VPN in my FortiGate and is up and working, but I don't know if my DPD configuration is correct or not. First of all I would like to know what is the main purpose of DPD, I understand it send packets over the VPN to check if the peer is up or not? But what happens when the peer is down? What does DPD do to solve the problem? Or what does DPD just do? On the other hand, there are two modes when it is enabled, "on idle" and "on demand", what is the difference between the two? I have read the documentation but is not clear.
Regards,
Julián
1st DPD comes into play when no traffic is sent over the IPSEC peer and at phase1
This ensure stale ipsec/ike peers are cleared
enable means we exclusively enable it regardless if it's negotiated by the party
on-demand means when a peer during the IKE exchange between Int/Responder that offers DPD, and then only than will the FGT use DPD
PCNSE
NSE
StrongSwan
Hi emnoc,
And "on idle"?
Regards,
Julián
On IDLE is when DPD takes places, if this dialup vpn than most likely NAT-T keepAlives are being used enlew of DPD. Keep in mind DPD is for when "IPSEC SAs are idle ", ( no need for DPD & if traffic is passing both ways at IPSEC payload )
PCNSE
NSE
StrongSwan
User | Count |
---|---|
2057 | |
1173 | |
770 | |
448 | |
341 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.