Hi all,
I have Checkpoint Gaia 80.20 that is connecting to AWS VPN site to site.
Based on the guidance of AWS site to site VPN, I have created two tunnel interfaces in my checkpoint to the AWS VPC and created BGP configuration, etc. I also set up the IKE and IPsec, NAT-T, permanent tunnel, and also Firewall configuration. Then the connection was successfully established. At that time I didn't use DPD, I used the default mode which was Tunnel Test.
My concern is I am using the network monitoring system that is using SNMP for the inbound and outbound of two tunnel interfaces traffic which is normal and no issues. I am also leveraging the QOS for those two tunnel interfaces in order to limit the traffic. But the issue is the connection in the AWS side which is intermittently up and down. Because of that I decided to use DPD mod for tunnel management then the connection to AWS was becoming great. After a few days, I just realized the traffic of two tunnel interfaces were not being monitored well. In actuality the traffic is operating at about tens Mbps, but the monitoring system was detecting it only operating some bps. I am sure there is no problem in my monitoring system. Therefore the QOS that I was using also did not work well.
Is there any issue if i use DPD so the tunnel interface traffic is not suitable as the real traffic? Because after I use DPD other than Tunnel Test, the tunnel interface traffic becomes an issue.