Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec DPD failure action

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance
      last edited by michmoor

      What is the failure action for pfsense when DPD is enabled?
      Typically the choices for when a peer doesnt respond to DPD is to restart the tunnel (phase 1 + phase2) or keep the tunnel down. I dont see any options in the GUI other than setting DPD and the timers.
      Also what is the reaction by pfSense if the peer doesnt support DPD so there is no DPD-ACK sent back?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        DPD must be enabled on both ends or it will not be enabled when the tunnel negotiates.

        If the DPD response fails the existing SADs are removed and the tunnel attempts to renegotiate.

        See: https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure-p1.html?highlight=dpd#advanced-options

        Steve

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.