Technical Tip: Configuring DPD (dead peer detection) on IPsec VPN (2024)

Description


This article describes how to configure DPD on IPsec VPN.

Sometimes, due to routing issues or other network issues, the communication link between a FortiGate unit and a VPN peer or client may go down.
Packets could be lost if the connection is left to time out on its own. The FortiGate unit provides a mechanism called Dead Peer Detection (DPD), sometimes referred to as gateway detection or ping server, to prevent this situation and to re-establish IKE negotiations automatically before a connection times out: the active Phase 1 security associations are caught and renegotiated (rekeyed) before the Phase 1 encryption key expires.

The commands in this article will help to configure DPD (dead peer detection) on IPsec VPN.

Scope

FortiClient.


Solution


It is possible to configure DPD per phase1-interface as follows (default settings are shown):

config vpn ipsec phase1-interface
edit <Tunnel Name>
set dpd [disable | on-idle | on-demand]
set dpd-retryinterval 20
set dpd-retrycount 3
next
end


DPD:
Disable: Disable Dead Peer Detection.
On-idle: Trigger Dead Peer Detection when no IPsec traffic is received.
On-demand: Trigger Dead Peer Detection when no IPsec traffic is received AND FortiGate has been sending IPsec traffic.

DPD-RETRYINTERVAL:
How long is the interval in seconds after which a DPD will be attempted again.

DPD-RETRYCOUNT:
How often will the DPD be attempted.

With the default settings, DPD will be attempted every 20 seconds, 3 times. In total after one minute without DPD responses the tunnel will be turned down.

On GUI:

Technical Tip: Configuring DPD (dead peer detection) on IPsec VPN (1)


On a dial-up server, if a multitude of VPN connections is idle, the increased DPD exchange could negatively impact the performance/load of the IKE process.
For this reason, an option is available in the CLI to send DPD passively in a mode called 'on-demand'.

  • When there is no traffic and the last DPD-ACK has been received, IKE will not send DPDs periodically.

IKE will only send out DPDs if there are outgoing packets to send but no inbound packets have since been received.

Crosscheck the DPD exchange with the diagnose tool on CLI:


diagnose debug console timestamp enable
diagnose debug application ike -1
diagnose debug enable


In IKEv1, DPD messages will be as 'R-U-THERE' and responses as 'R-U-THERE-ACK':

ike 3:testVPN:123123: sent IKE msg (R-U-THERE): 1.2.3.4:500->4.3.2.1:500, len=92, id=8357cf8e359f24b8/e7763893c7180208:2ab66f73
...
ike 3:testVPN:123123: notify msg received: R-U-THERE-ACK

In IKEv2, the message will be 'informational':

2021-02-10 16:20:48.645409 ike 0:VPN-test:9: send IKEv2 DPD probe
2021-02-10 16:20:48.645478 ike 0:VPN-test:21: sending NOTIFY msg
2021-02-10 16:20:48.645543 ike 0:VPN-test:9:21: send informational

For further information, refer to the 'FortiGate/FortiOS Documentation' manual which is available in the Fortinet Document Library.

Technical Tip: Configuring DPD (dead peer detection) on IPsec VPN (2024)
Top Articles
Corporate/M&A & Private Equity, Florida: South, USA | Chambers Rankings
The Cost Of A Mortgage Across Time #INFOGRAPHIC
Victor Spizzirri Linkedin
Dricxzyoki
Black Gelato Strain Allbud
The Best Classes in WoW War Within - Best Class in 11.0.2 | Dving Guides
Victoria Secret Comenity Easy Pay
Danielle Longet
What’s the Difference Between Cash Flow and Profit?
zopiclon | Apotheek.nl
Dutchess Cleaners Boardman Ohio
Overton Funeral Home Waterloo Iowa
Chic Lash Boutique Highland Village
Viprow Golf
9044906381
Dr Adj Redist Cadv Prin Amex Charge
Equipamentos Hospitalares Diversos (Lote 98)
Star Wars: Héros de la Galaxie - le guide des meilleurs personnages en 2024 - Le Blog Allo Paradise
Parent Resources - Padua Franciscan High School
Praew Phat
Apply for a credit card
Nearest Walgreens Or Cvs Near Me
Ein Blutbad wie kein anderes: Evil Dead Rise ist der Horrorfilm des Jahres
Barber Gym Quantico Hours
Maxpreps Field Hockey
Lexus Credit Card Login
Ficoforum
897 W Valley Blvd
Nurofen 400mg Tabletten (24 stuks) | De Online Drogist
Craigslist/Phx
100 Million Naira In Dollars
Selfservice Bright Lending
Solemn Behavior Antonym
Imperialism Flocabulary Quiz Answers
Ise-Vm-K9 Eol
Frommer's Philadelphia &amp; the Amish Country (2007) (Frommer's Complete) - PDF Free Download
Callie Gullickson Eye Patches
Beaufort SC Mugshots
Carteret County Busted Paper
814-747-6702
Tableaux, mobilier et objets d'art
Ehome America Coupon Code
Whitney Wisconsin 2022
DL381 Delta Air Lines Estado de vuelo Hoy y Historial 2024 | Trip.com
Headlining Hip Hopper Crossword Clue
Colin Donnell Lpsg
17 of the best things to do in Bozeman, Montana
Slug Menace Rs3
Rétrospective 2023 : une année culturelle de renaissances et de mutations
Diesel Technician/Mechanic III - Entry Level - transportation - job employment - craigslist
Wayward Carbuncle Location
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6076

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.