Fortinet FortiGate FortiGate-1000 Administration Manual page 276

Fortinet fortigate fortigate-1000: user guide
Hide thumbs Also See for FortiGate FortiGate-1000:
Table of Contents

Advertisement

CLI configuration
276
ipsec phase1 command keywords and variables
Keywords and
variables
dpd-idlecleanup
<seconds_integer>
dpd-idleworry
<seconds_integer>
dpd-retrycount
<retry_integer>
dpd-retryinterval
<seconds_integer>
01-28006-0009-20041105
Description
The DPD long idle setting when dpd is set
to enable. Set the time, in seconds, that a
link must remain unused before the local
VPN peer pro-actively probes its state. After
this period of time expires, the local peer
will send a DPD probe to determine the
status of the link even if there is no traffic
between the local peer and the remote
peer. The dpd-idlecleanup range is 100
to 28 800 and must be greater than the
dpd-idleworry setting.
The DPD short idle setting when dpd is set
to enable. Set the time, in seconds, that a
link must remain unused before the local
VPN peer considers it to be idle. After this
period of time expires, whenever the local
peer sends traffic to the remote VPN peer it
will also send a DPD probe to determine
the status of the link. The dpd-idleworry
range is 1 to 300.
To control the length of time that the
FortiGate unit takes to detect a dead peer
with DPD probes, use the dpdretrycount
and dpd-retryinterval keywords.
The DPD retry count when dpd is set to
enable. Set the number of times that the
local VPN peer sends a DPD probe before
it considers the link to be dead and tears
down the security association (SA). The
dpd-retrycount range is 0 to 10.
To avoid false negatives due to congestion
or other transient failures, set the retry
count to a sufficiently high value for your
network.
The DPD retry interval when dpd is set to
enable. Set the time, in seconds, that the
local VPN peer waits between sending DPD
probes. The dpd-retryinterval range
is 1 to 60.
VPN
Default
Availability
300
All models.
seconds
dpd must
be set to
enable.
10
All models.
seconds
dpd must
be set to
enable.
3
All models.
dpd must
be set to
enable.
5
All models.
seconds
dpd must
be set to
enable.
Fortinet Inc.

Advertisement

Table of Contents
loading

Table of Contents