The ike dpd command enables the dead peer detection (DPD) function.
The undo ike dpd command restores the default configuration.
By default, the DPD function is disabled
This command is supported only on the NetEngine 8000 F1A.
Parameter | Description | Value |
---|---|---|
check-interval |
Indicates the interval of transmitting DPD packets. |
It is an integer that ranges from 10 to 3600, in seconds. |
retry-interval |
Indicates the interval of timeout retransmission of DPD packets. |
It is an integer that ranges from 2 to 60, in seconds. The default value is 5 seconds. |
on-demand |
Indicates that the DPD function works in traffic-triggering mode. |
- |
immediately |
Indicates the mode of becoming effective immediately. |
- |
interval |
Indicates that the DPD function works in polling mode. |
- |
Usage Scenario
Pay attention to the following items:
Precautions
The IKE DPD function must be configured so that both ends of an IPsec tunnel can detect the peer status and maintain consistent IPsec tunnel status to ensure uninterrupted IPsec services.
When using the IKEV1 version, IKE DPD must be configured at both ends of the IPsec tunnel at the same time, otherwise the DPD function will not take effect.