Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Site to Site VPN Question

Status
Not open for further replies.

ajb822

IS-IT--Management
May 9, 2002
11
US
I have a device that is required to periodically send a 3 byte UDP packet to the a host on the other side of a site-to-site VPN tunnel. What I am finding is that if the tunnel has already been built the UDP packet makes it to the host fine, however, if the tunnel isn't up, the UDP packet initates the tunnel but the packet doesnt reach the host. It seems like the UDP packet initates the building of the tunnel but is being dropped. I'm kinda a newbie, just wondering if this makes sense.

Thanks

Tony Barnette
 
UDP is an unreliable protocol. If the PIX sees the packet as interesting traffic the tunnel will be established. But the sending device doesn't care if the packet is received on the other end...therefor you are probably experiencing this issue.

One way to possible solve this would be to enabled DPD (Dead Peer Detection) on the VPN...so the VPN stay's online all the time. Then when the packet is sent...it can go thru an already live VPN tunnel and potentially reach the destination.
 
kbing,

do you have any documentation on DPD?

it sounds interesting and i have never seen it

Thanks

 
Thanks for the info. Validates what we are seeing here.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top