You are on page 1of 1


On idle- trigger dpd messages when no traffic is send through the tunnel.

With the default settings DPD will attempted every 20 seconds, 3 times. In total after one minute
without dpd responses the tunnel will be turned down.

On demand; trigger DPD messages when IPsec traffic is sent through the tunnel but no reply is received.

In the example bellow I am using DPD on demand. I am sending ping from towards Initially traffic flows through the primary VPN.

20 seconds after shutting the primary link DPD was triggered. After 3th attempt the primary VPN route
was removed from the routing table and Secondary IPsec tunnel was established.

At the moment when I return the primary, VPN link primary IPSec tunnel was almost instantly

You might also like