<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN and DPD configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59582#M12532</link>
    <description>My understanding is you only configure DPD on the gateway objects where DPD is actually required.&lt;BR /&gt;You do not need to configure your local object to use DPD.&lt;BR /&gt;See related discussion here: &lt;A href="https://community.checkpoint.com/t5/General-Topics/Enable-DPD-on-R80-20/m-p/32605" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Enable-DPD-on-R80-20/m-p/32605&lt;/A&gt;</description>
    <pubDate>Sun, 04 Aug 2019 18:03:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-08-04T18:03:45Z</dc:date>
    <item>
      <title>VPN and DPD configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59472#M12531</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;in according to the R80.10 VPN documentation, for enabling DPD as method for the permanent tunnel, I need to change the parameter &lt;STRONG&gt;tunnel_keepalive_method property for each gateway in the community.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;With the statement "for each gateway in the community" means you have to perform the change at the remote peer object and at the CKP gateway object as well.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The same CKP gw object is used in other VPN community with permanent tunnel on but based on tunnel_test protocol because s2s with other CKP gateway.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm worried about the impact it could introduce.&lt;/P&gt;&lt;P&gt;My question is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; what happens if I will configure the parameter to DPD on ckpgw used in different community?&lt;/P&gt;&lt;P&gt;I'd like to know what is the permanent tunnel protocol used in the following scenario&lt;/P&gt;&lt;P&gt;ckpgw1 &lt;STRONG&gt;tunnel_keepalive_method&lt;/STRONG&gt;: dpd&lt;/P&gt;&lt;P&gt;ckpgw2 &lt;STRONG&gt;tunnel_keepalive_method&lt;/STRONG&gt;: tunnel_test&lt;/P&gt;&lt;P&gt;3rdgw1: dpd&lt;/P&gt;&lt;P&gt;VPN community1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; center gateway: ckpgw1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; satellite gateway: ckpgw2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permanent tunnel: on all tunnels in the community&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;keepalive is based on .... (dpd/tunnel_test/not working)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;VPN community2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; center gateway: ckpgw1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; satellite gateway: 3rdgw1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permanent tunnel: on all tunnels in the community&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;keepalive is based on .... (dpd/tunnel_test/not working)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;thank you in advanced&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 07:12:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59472#M12531</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2019-08-02T07:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and DPD configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59582#M12532</link>
      <description>My understanding is you only configure DPD on the gateway objects where DPD is actually required.&lt;BR /&gt;You do not need to configure your local object to use DPD.&lt;BR /&gt;See related discussion here: &lt;A href="https://community.checkpoint.com/t5/General-Topics/Enable-DPD-on-R80-20/m-p/32605" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Enable-DPD-on-R80-20/m-p/32605&lt;/A&gt;</description>
      <pubDate>Sun, 04 Aug 2019 18:03:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59582#M12532</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-04T18:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and DPD configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59735#M12533</link>
      <description>&lt;P&gt;Thanks PhoneBoy&lt;/P&gt;&lt;P&gt;Just for starting, the discussion in the post &lt;A href="https://community.checkpoint.com/t5/General-Topics/Enable-DPD-on-R80-20/m-p/32605" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Enable-DPD-on-R80-20/m-p/32605&lt;/A&gt; sounds related to DPD passive mode.&lt;/P&gt;&lt;P&gt;In my configuration I need &lt;EM&gt;Permanent Tunnel based on DPD mode&lt;/EM&gt; and, in according to the guide sk108600 scenario 5, I have to switch to DPD event on my local gateway&lt;/P&gt;&lt;P&gt;Moreover I tried to investigate the configuration when DPD is enabled on remote peer object and not in local object and when it configured on both object.&lt;/P&gt;&lt;P&gt;in the first testing scenario the packtet was tunnel_test; while the 2nd scenario the packet is DPD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 15:41:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-and-DPD-configuration/m-p/59735#M12533</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2019-08-06T15:41:19Z</dc:date>
    </item>
  </channel>
</rss>

