sk108600 VPN Site-to-Site with 3rd party - Scenario 5
AWS side has DPD enabled. They report issues where two tunnels come up, one initiator and one as responder. The tunnel works fine until it locks up. The remote side has to reset their side to bring back up.
I am looking at "Passive DPD Responder Mode". This is a registry edit on my Check Point firewalls.
If I understand correctly, the would allow the Check Point to respond to the AWS side's probing.
Question: Is this generally safe to enable this registry setting on my gateway without impacting the other IPSec tunnels I have? (which are working)
I am aware of enabling permanent tunnel and modifying the interoperable device with GuiDBEdit; however that apparently allows my gateway to initiate tunnels to AWS which is the problem I'm trying to solve.