Configuring The Ike Keepalive Feature; Configuring The Ike Nat Keepalive Feature; Configuring Ike Dpd - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring the IKE keepalive feature

IKE sends keepalive packets to query the liveness of the peer. If the peer is configured with the
keepalive timeout time, you must configure the keepalive interval on the local device. If the peer
receives no keepalive packets during the timeout time, the IKE SA is deleted along with the IPsec
SAs it negotiated.
Follow these guidelines when you configure the IKE keepalive feature:
Configure IKE DPD instead of IKE keepalive unless IKE DPD is not supported on the peer. The
IKE keepalive feature sends keepalives at regular intervals, which consumes network
bandwidth and resources.
The keepalive timeout time configured on the local device must be longer than the keepalive
interval configured at the peer. Since it seldom occurs that more than three consecutive packets
are lost on a network, you can set the keepalive timeout three times as long as the keepalive
interval.
To configure the IKE keepalive feature:
Step
1.
Enter system view.
2.
Set the IKE SA keepalive
interval.
3.
Set the IKE SA keepalive
timeout time.

Configuring the IKE NAT keepalive feature

If IPsec traffic passes through a NAT device, you must configure the NAT traversal feature. If no
packet travels across an IPsec tunnel in a period of time, the NAT sessions are aged and deleted,
disabling the tunnel from transmitting data to the intended end. To prevent NAT sessions from being
aged, configure the NAT keepalive feature on the IKE gateway behind the NAT device to send NAT
keepalive packets to its peer periodically to keep the NAT session alive.
To configure the IKE NAT keepalive feature:
Step
1.
Enter system view.
2.
Set the IKE NAT keepalive
interval.

Configuring IKE DPD

DPD detects dead peers. It can operate in periodic mode or on-demand mode.
Periodic DPD—Sends a DPD message at regular intervals. It features an earlier detection of
dead peers, but consumes more bandwidth and CPU.
On-demand DPD—Sends a DPD message based on traffic. When the device has traffic to
send and is not aware of the liveness of the peer, it sends a DPD message to query the status of
the peer. If the device has no traffic to send, it never sends DPD messages. As a best practice,
use the on-demand mode.
The IKE DPD works as follows:
Command
system-view
ike keepalive interval seconds
ike keepalive timeout seconds
Command
system-view
ike nat-keepalive seconds
321
Remarks
N/A
By default, no keepalives are sent
to the peer.
By default, IKE SA keepalive
never times out.
Remarks
N/A
The default interval is 20 seconds.

Advertisement

Table of Contents
loading

Table of Contents