[strongSwan] DPD Questions

Martin Willi martin at strongswan.org
Wed Aug 8 09:59:28 CEST 2012


Hi Terry,

> My value was set at 500 as shown above, but I didn't see the first
> attempt to send an R-U-THERE query until over 15 minutes after I
> terminated all communications between the peers

If an ESP packet is received, the DPD delay timer is reset, as we know
the SA is still up. So a first R-U-THERE is not sent before 500s after
the last ESP/IKE packet from the peer has been seen.

Regards
Martin





More information about the Users mailing list