IPsec Tunnel DPD does not work

René Moser <[email protected]>
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
Hi

I am using 2 m0n0walls behind 2 dyn IPs (WAN). I am using DynDNS on both
systems. Both systems receiving a new IP every ~24h. (DynDNS default TTL
of CNAME is 60s)

I configured an IPsec tunnel on both systems, running fine. But after IP
change, the tunnel is dead. My IPsec config has a DPD of 60s (default).

When I restart racoon (disable/enable IPSec), the tunnel is up again
immediately.

I am expecting m0n0wall should detect the dead pear and restart the tunnel.
Am I wrong? Or what does DPD (Dead Peer Detection) stand for?

-- 
René Moser
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.