- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- What value does DPD have on timeout?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What value does DPD have on timeout?
I have a S2S VPN with AWS, where I did the setting of the DPD value as indicated by their AWS best practices. (by default in R80.xx version it is enabled)
The AWS administrator indicates that it has configured the value "DPD Timeout (seconds) with value 30".
The AWS administrator ask me that on the Checkpoint side, which value has the same parameter "DPD Timeout" configured. However, I have already been looking for this value and I cannot find where the value is specified.
Does anyone know what DPD Timeout value does the Checkpoint use?
additional disconnections continue to occur in the VPN with AWS.
If from my side I generate traffic the VPN the tunnel is UP, however, if AWS tries to generate traffic it is not able to establish the VPN tunnel again.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think DPD reuses the "life sign" timers located here in the SmartConsole:
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'll be honest, I've never seen a timeout setting related to DPD.
Did you happen to configure a "permanent tunnel" which may be what you want here?
See Scenario 5 here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AWS cannot initiate the tunnel, it has to be always open from CP side. Look into sk108600, specifically Scenario 5, for resolution steps. Timeout value does not matter, you just need to configure keep-alive properly, as the case specifies.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think DPD reuses the "life sign" timers located here in the SmartConsole:
CET (Europe) Timezone Course Scheduled for July 1-2
