<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check Point DPD (Dead Peer Detection) - Questions in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48075#M9375</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have two questions regarding the Dead Peer Detection between our Check Point Cluster and other existing VPN connections to non-Check Point Gateways.&lt;/P&gt;&lt;P&gt;1. Does enabling DPD (Responder Mode) has any impact on existing VPN connections? Can I enable it "on-the-fly" without having any disconnects to the VPN? I haven't found an answer on that yet.&lt;/P&gt;&lt;P&gt;2. If I change a VPN community with non-Check Point Gateways to "Permanent Tunnels" in order to active DPD with GuiDBedit does this have any impact on existing connections?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2019 09:13:17 GMT</pubDate>
    <dc:creator>Marcel_Gramalla</dc:creator>
    <dc:date>2019-03-21T09:13:17Z</dc:date>
    <item>
      <title>Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48075#M9375</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have two questions regarding the Dead Peer Detection between our Check Point Cluster and other existing VPN connections to non-Check Point Gateways.&lt;/P&gt;&lt;P&gt;1. Does enabling DPD (Responder Mode) has any impact on existing VPN connections? Can I enable it "on-the-fly" without having any disconnects to the VPN? I haven't found an answer on that yet.&lt;/P&gt;&lt;P&gt;2. If I change a VPN community with non-Check Point Gateways to "Permanent Tunnels" in order to active DPD with GuiDBedit does this have any impact on existing connections?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 09:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48075#M9375</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-03-21T09:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48076#M9376</link>
      <description>quickly though:&lt;BR /&gt;&lt;BR /&gt;Ad.1 - it will re-estab SA/SPI indeed&lt;BR /&gt;Ad.2. - it will re-estab the tunnel&lt;BR /&gt;&lt;BR /&gt;ps. any changes to the proxy-id or any crypt.conf params will re-key and re-estab SA/SPI</description>
      <pubDate>Thu, 21 Mar 2019 09:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48076#M9376</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-21T09:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48080#M9377</link>
      <description>Thanks for the quick reply. That means that we have to announce it so that if there is any issue our partners know about it.</description>
      <pubDate>Thu, 21 Mar 2019 09:33:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48080#M9377</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-03-21T09:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48081#M9378</link>
      <description>it will in 100% impact/affect an existing tunnel(s) so yes, that should be announced and planed for so called "maintenance window" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;cheers</description>
      <pubDate>Thu, 21 Mar 2019 09:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/48081#M9378</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-21T09:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/62495#M12671</link>
      <description>&lt;P&gt;Is there any way to check if DPD is enabled?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:07:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/62495#M12671</guid>
      <dc:creator>Ravindra_Katrag</dc:creator>
      <dc:date>2019-09-11T16:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/64514#M13145</link>
      <description>&lt;P&gt;Yes, there is. You can check with the GuiDBedit tool under Network Objects &amp;gt;&amp;gt; network_objects:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DPD.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2711iD630BAFDA3DAA496/image-size/large?v=v2&amp;amp;px=999" role="button" title="DPD.PNG" alt="DPD.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 09:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/64514#M13145</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2019-10-08T09:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/66359#M13595</link>
      <description>&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 14:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/66359#M13595</guid>
      <dc:creator>Ravindra_Katrag</dc:creator>
      <dc:date>2019-10-31T14:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/66513#M13645</link>
      <description>&lt;P&gt;My pleasure!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 14:54:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/66513#M13645</guid>
      <dc:creator>Nick_Doropoulos</dc:creator>
      <dc:date>2019-11-04T14:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/66586#M13654</link>
      <description>&lt;P&gt;Can we achieve VPN redundancy with 3rd party Gateways by enabling DPD(In R80.10 or R80.20) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 12:15:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/66586#M13654</guid>
      <dc:creator>nagaraja_cs</dc:creator>
      <dc:date>2019-11-05T12:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/91964#M18330</link>
      <description>&lt;P&gt;Can we enable Dead Peer detection on the third party devices only? &amp;nbsp;Or do we have to enable it on the checkpoint gateways also? My understanding is if enabled on the checkpoint gateways it affects all other VPNs?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/91964#M18330</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2020-07-20T19:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/92001#M18332</link>
      <description>&lt;P&gt;You can set DPD per remote gateway via the&amp;nbsp;&lt;STRONG&gt;tunnel_keepalive_method&lt;/STRONG&gt; variable in GUIDBedit as described in this lengthy thread, you don't have to change this value for your Check Point gateway:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Next-Generation-Firewall/Enable-DPD-on-R80-20/m-p/32605" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Next-Generation-Firewall/Enable-DPD-on-R80-20/m-p/32605&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Starting in R81&amp;nbsp;&lt;STRONG&gt;tunnel_keepalive_method&lt;/STRONG&gt; will be set to DPD by default on all Interoperable Device object types.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 04:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/92001#M18332</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-21T04:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/98142#M19212</link>
      <description>&lt;P&gt;Do you know how to capture DPD packets in any way? I could see tunnel test in the logs, but seem to be missing how to spot DPD packets. I can't see them in TCPDUMP as they are encrypted. I would really appreciate some guidance on this. I am working on an AWS VPN issue where I think the tunnels are being shut down regularly and I would like to spot what is going on. I have a TAC case open but every time I ask the question they seem to swerve around it.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2020 15:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/98142#M19212</guid>
      <dc:creator>Gavin</dc:creator>
      <dc:date>2020-10-04T15:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/98160#M19215</link>
      <description>&lt;P&gt;fw monitor should show the packets as they are encrypted/decrypted.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2020 16:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/98160#M19215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-04T16:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point DPD (Dead Peer Detection) - Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/167906#M27895</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hussien_Wahab_0-1673868297596.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19148i468181346BB94E72/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Hussien_Wahab_0-1673868297596.png" alt="Hussien_Wahab_0-1673868297596.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;AWS sends "isakmp-nat-keep-alive" packets that are outside the DPD tunnel health monitoring, please see the packets in red (the ones in blue are for the actual DPD that keeps the tunnel status up and alive)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 11:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-DPD-Dead-Peer-Detection-Questions/m-p/167906#M27895</guid>
      <dc:creator>Hussien_Wahab</dc:creator>
      <dc:date>2023-01-16T11:25:47Z</dc:date>
    </item>
  </channel>
</rss>

