Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SecNetEng
Contributor
Jump to solution

IPSec VPN to AWS - DPD responder

sk108600 VPN Site-to-Site with 3rd party - Scenario 5

AWS side has DPD enabled. They report issues where two tunnels come up, one initiator and one as responder. The tunnel works fine until it locks up. The remote side has to reset their side to bring back up.

I am looking at "Passive DPD Responder Mode". This is a registry edit on my Check Point firewalls.

If I understand correctly, the would allow the Check Point to respond to the AWS side's probing.

Question: Is this generally safe to enable this registry setting on my gateway without impacting the other IPSec tunnels I have? (which are working)

I am aware of enabling permanent tunnel and modifying the interoperable device with GuiDBEdit; however that apparently allows my gateway to initiate tunnels to AWS which is the problem I'm trying to solve.

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

This should be safe to do.
If one of your VPN peers requires responder mode, this can be forced per-peer through Guidbedit.

View solution in original post

1 Reply
PhoneBoy
Admin
Admin

This should be safe to do.
If one of your VPN peers requires responder mode, this can be forced per-peer through Guidbedit.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events