CISCO ASA ISAKMP KEEPALIVE – DPD

Dead Peer Detection – DPD

DPD on ASA

ASA and PIX firewalls support “semi-periodic” DPD only. I.e. they send R-U-THERE message to
a peer if the peer was idle for <threshold> seconds. ASA may have nothing to send to the peer,
but DPD is still sent if the peer is idle. If the VPN session is comletely idle the R-U-THERE messages
are sent every <threshold> seconds. If there is a traffic coming from the peer the R-U-THERE
messages are not sent.

Unlike routers, you can completely disable DPD on ASA and it will not negotiate it with a peer
(“disable” configuration option).

Also, you can configure “one-way” DPD mode on ASA. The ASA will respond to R-U-THERE
messages, but will not initiate DPD exchange (“threshold infinite” configuration option).

isakmp keepalive {disable | threshold <threshold> retry <retry-interval> | threshold infinite}

If the peer doesn’t respond with the R-U-THERE-ACK the ASA starts retransmitting R-U-THERE
messages every <retry-interval> seconds with a maximum of three retransmissions.
After that the peer is declared dead.

You cannot specify the number of retries on ASA.

DPD is enabled by default on ASA for both L2L and RA IPSec:

tunnel-group DefaultRAGroup ipsec-attributes
isakmp keepalive threshold 300 retry 2

In brief, on ASA we have the following:

only “semi-periodic” DPD is supported
DPD can be completely disabled
one-way mode is supported
bidirectional mode is the default one
retry interval can be configured
retry count cannot be configured and equals to three

Recommended Settings :

ASA :

tunnel-group DefaultL2LGroup ipsec-attributes
isakmp keepalive threshold 20 retry 2

CISCO ROUTER :

crypto isakmp profile 1
keepalive interval 20 retry 2

Allows the gateway to send DPD messages to the peer.

•seconds—Number of seconds between DPD messages.
•retries—(Optional) Number of seconds between DPD retries if the DPD message fails.
•periodic—(Optional) DPD messages are sent at regular intervals.
•on-demand—(Optional) DPD retries are sent on demand. This is the default behavior.

command on ASA’s/PIX’s to view the status of isakmp keepalives?

This command shows you how long it has been since a keepalive has been received.

show vpn-sessiondb detail l2l
show crypto isakmp sa detail

If the remote VPN peer initiates a site-to-site tunnel using aggressive mode, then the ASA uses that
for tunnel negotiations. Aggressive mode has some security weaknesses, so it is recommended to use
main mode where possible.

However, if you do not want to accept connections using aggressive mode, you can disable it globally,

Disabling Aggressive Mode
crypto isakmp am-disable