Virtual Private Networking Using IPSec and L2TP Connections
260
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
For DPD to function, the peer VPN device on the other end of the tunnel also needs to
support DPD. Keep-alive, though less reliable than DPD, does not require any support from
the peer device.
Configure Keep-Alives
The keep-alive feature maintains the IPSec SA by sending periodic ping requests to a host
across the tunnel and monitoring the replies.
To configure the keep-alive feature on a configured VPN policy:
1. Select VPN > IPSec VPN > VPN Policies. The VPN Policies screen displays the IPv4
settings (see Figure 156 on page 232).
2. Specify the IP version for which you want to edit a VPN policy:
IPv4. In the upper right of the screen, the IPv4 radio button is already selected by
default. Go to Step 3.
IPv6. Select the IPv6 radio button. The VPN Policies screen for IPv6 displays.
3. In the List of VPN Policies table, click the Edit table button to the right of the VPN policy that
you want to edit. The Edit VPN Policy screen displays. (The following figure shows only the
top part with the General section of the Edit VPN Policy screen for IPv6.)
Figure 172.