DPD

DPD monitors the state of an IPsec tunnel. If a tunnel down event is detected the SAs associated with the tunnel are destroyed. This helps in getting the tunnel up quickly: assume the old SA is still regarded as valid when the remote side tries to re-establish a tunnel after it broke off. An SA mismatch would happen and prevent the tunnel from coming up.

https://kb.fortinet.com/kb/documentLink.do?externalID=FD35337

SA - security association (SA) is fundamental to IPSec. An SA is a relationship between two or more entities that describes how the entities will use security services to communicate securely.

https://www.ciscopress.com/articles/article.asp?p=24833&seqNum=7

Last updated

Was this helpful?