Dead peer detection (DPD)

This method of connection monitoring is used when VPN clients dial-in to a VPN gateway. This is designed to ensure that a client is logged out if there is an interruption to the VPN connection, for example when the Internet connection is interrupted briefly. If the line were not to be monitored, then the VPN gateway would continue to list the client as logged-on. This would prevent the client from logging in again as, for example, the WLANmonitor prevents single serial numbers from multiple simultaneous log-ins.

Note: For the same reason, without line monitoring a user with the same "identity" (user name) would be prevented from dialling in because the associated user would still be in the list for the logged-in client.

With dead peer detection, the gateway and client regularly exchange "keep alive" packets. If no replies are received, the gateway will log out the client so that this identity can be registered anew once the VPN connection has been re-established. The DPD time for VPN clients is typically set to 60 seconds.

The dead peer detection is set up with LANconfig in the configuration area 'VPN' on the 'General' tab in the 'Connection list'.





LANconfig: VPN / General / Connection list

WEBconfig: LCOS menu tree / Setup / VPN E VPN-Peers