IPsec DPD failure action
-
What is the failure action for pfsense when DPD is enabled?
Typically the choices for when a peer doesnt respond to DPD is to restart the tunnel (phase 1 + phase2) or keep the tunnel down. I dont see any options in the GUI other than setting DPD and the timers.
Also what is the reaction by pfSense if the peer doesnt support DPD so there is no DPD-ACK sent back? -
DPD must be enabled on both ends or it will not be enabled when the tunnel negotiates.
If the DPD response fails the existing SADs are removed and the tunnel attempts to renegotiate.
Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.