Dpd - HP 5920 Command Reference Manual

Table of Contents

Advertisement

Field
Exchange-mode
Diffie-Hellman group
NAT traversal

dpd

Use dpd to enable the device to send DPD messages.
Use undo dpd to disable the IKE DPD function.
Syntax
dpd interval interval-seconds [ retry seconds ] { on-demand | periodic }
undo dpd interval
Default
IKE DPD is disabled.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
interval interval-seconds: Specifies a period of time in seconds. The value range is from 1 to 300.
If the on-demand keyword is specified, this parameter specifies the number of seconds during
which no IPsec packet is received before DPD is triggered if the local has IPsec traffic to send.
If the periodic keyword is specified, this parameter specifies a DPD triggering interval.
retry seconds: Specifies the number of seconds between DPD retries if the DPD message fails. The value
for the second argument is from 1 to 60 seconds, and defaults to 5 seconds.
on-demand: Sends DPD messages on demand.
periodic: Sends DPD messages at regular intervals.
Usage guidelines
DPD is triggered periodically or on-demand. The on-demand mode is recommended when the device
communicates with a large number of IKE peers. For an earlier detection of dead peers, use the periodic
triggering mode, which consumes more bandwidth and CPU.
When DPD settings are configured in both IKE profile view and system view, the DPD settings in IKE
profile view apply. If DPD is not configured in IKE profile view, the DPD settings in system view apply.
It is a good practice to set the triggering interval longer than the retry interval so that a DPD detection are
not triggered during a DPD retry.
Description
IKE negotiation mode in phase 1, main mode or aggressive mode.
DH group used for key negotiation in IKE phase 1.
Whether NAT traversal is detected.
374

Advertisement

Table of Contents
loading

This manual is also suitable for:

59005920 series5900 series

Table of Contents