To detect issues with an IKE gateway for the remote network connection, Nuage
Networks VNS uses the Dead Peer Detection (DPD) mechanism, in addition to using
a probing mechanism to probe internet services.
The probes are divided into two hierarchical levels: Tier1 and Tier2. Nuage
Networks initiates the probe. The Tier 1 probe tests the connectivity of the
remote network connection to Prisma Access and the Tier 2 probe tests the
connectivity to the internet.
Each connection is composed of an Active IPSec tunnel (priority 100) and a backup
IPSec tunnel (priority 200). The HTTP probes run on both connections.
Tier 1 Probe—Each Tier1 probe is associated to a weight (between 1
and 100%). For Tier1 to fail, the sum of the Tier1 probes that fail must
be equal to or greater than 100%. If the Tier1 probe goes down, Tier 2
probe monitoring also goes down.
Tier 2 Probe—The Tier 2 probe uses round-robin monitoring across a
set of internet FQDNs. Consecutive probe tests must fail for the Tier2
probe to fail.