Cisco Cisco Packet Data Interworking Function (PDIF) Prospecto
Redundant IPSec Tunnel Fail-over
▀ Dead Peer Detection (DPD) Configuration
▄ Cisco StarOS IP Security (IPSec) Reference
106
Dead Peer Detection (DPD) Configuration
This section provides instructions for configuring the Dead Peer Detection (DPD).
Defined by RFC 3706, Dead Peer Detection (DPD) is used to simplify the messaging required to verify communication
between peers and tunnel availability.
between peers and tunnel availability.
DPD is configured at the context level and is used in support of the IPSec Tunnel Failover feature (refer to the
Redundant IPSec Tunnel Fail-Over section) and/or to help prevent tunnel state mismatches between an FA and HA
when IPSec is used for Mobile IP applications. When used with Mobile IP applications, DPD ensures the availability of
tunnels between the FA and HA. (Note that the starIPSECDynTunUp and starIPSECDynTunDown SNMP traps are
triggered to indicate tunnel state for the Mobile IP scenario.)
Redundant IPSec Tunnel Fail-Over section) and/or to help prevent tunnel state mismatches between an FA and HA
when IPSec is used for Mobile IP applications. When used with Mobile IP applications, DPD ensures the availability of
tunnels between the FA and HA. (Note that the starIPSECDynTunUp and starIPSECDynTunDown SNMP traps are
triggered to indicate tunnel state for the Mobile IP scenario.)
Regardless of the application, DPD must be supported/configured on both security peers. If the system is configured
with DPD but it is communicating with a peer that does not have DPD configured, IPSec tunnels still come up.
However, the only indication that the remote peer does not support DPD exists in the output of the show crypto isakmp
security-associations summary command.
with DPD but it is communicating with a peer that does not have DPD configured, IPSec tunnels still come up.
However, the only indication that the remote peer does not support DPD exists in the output of the show crypto isakmp
security-associations summary command.
Important:
If DPD is enabled while IPSec tunnels are up, it will not take affect until all of the tunnels are
cleared.
Important:
DPD must be configured in the same StarOS context as other IPSec Parameters.
To configure the Crypto group to support IPSec:
Step 1
Enable dead peer detection on system in support of the IPSec Tunnel Failover feature by following the steps in
Step 2
Step 3
Save your configuration to flash memory, an external memory device, and/or a network location using the Exec mode
command save configuration. For additional information on how to verify and save configuration files, refer to the
System Administration Guide and the Command Line Interface Reference.
command save configuration. For additional information on how to verify and save configuration files, refer to the
System Administration Guide and the Command Line Interface Reference.
Configuring DPD for a Crypto Group
Use the following example to configure a crypto group on your system for redundant IPSec tunnel fail-over support:
configure
context <ctxt_name>
ikev1 keepalive dpd interval <dur> timeout <dur> num-retry <retries>
end
Notes:
<ctxt_name>
is the destination context where the Crypto Group is to be configured.