VPN Keep-Alives
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Configure Branch HA in a Hybrid Topology with Gen-1 (3000) and Gen-2 (3200) Platforms
- Prisma SD-WAN Incidents and Alerts
VPN Keep-Alives
VPN keep-alive packets determine whether a given path is reachable for an Prisma SD-WAN.
You can configure VPN Keep-Alives for circuit categories, circuits, and Secure Fabric
Links.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
VPN keep-alive packets determine whether a given path is reachable for
an ION device. VPN keep-alive packets are sent at a fixed interval on a VPN link.
The VPN link is declared down, if the peer is unreachable after a certain number of
attempts and a certain period of time.
The location of the ION device in a network topology plays an important role in
configuring VPN keep-alives. For example, you need to configure a higher value of
the keep-alive Interval between two ION devices behind routers as compared to the
keep-alive Interval between two ION devices not behind routers.
VPN keep-alives are configured at the following levels:
- Configure VPN Keep-Alives for Circuit Categories
- Configure VPN Keep-Alives for Circuits
- Configure VPN Keep-Alives for Secure Fabric Links
The order of precedence for VPN keep-alives is as follows:
- VPN keep-alives configured at the secure fabric link level have the highest priority.
- If VPN keep-alives are not configured at the secure fabric link level, then VPN keep-alives configured at the circuits level take effect.
- If VPN keep-alives are not configured at both secure fabric link level and circuits level, then VPN keep-alives configured at the circuit categories level take effect.
If there is a mismatch in configuration between two VPN endpoints, then:
- The keep-alive configuration with the larger keep-alive interval takes effect.
- If keep-alive intervals are the same, then the configuration with the higher keep-alive failure count takes effect.
Configure VPN Keep-Alives for Circuit Categories
For metered links, where there is a cost for usage (such as LTE interfaces), VPN
keep-alives can be adjusted to minimize the usage of the link and any costs
associated with using the link. VPN keep-alives can also be modified for
unreliable circuits that experience high latency and loss such as
satellites.
- Select Manage, Resources, and then select Circuit Categories.Edit a circuit category and enter values for Keep-Alive Failure Count and Keep-Alive Interval.
- For Keep-Alive Failure Count, enter a value between 3 and 30.The Keep-Alive Failure Count indicates the number of consecutive missed keep-alive packets before a link is declared as down. The default value is 3.
- For Keep-Alive Interval, enter a value between 100 ms and 600000 ms.The Keep-Alive Interval indicates the time interval in milliseconds between two VPN keep-alive packets. The default value is1000 ms.
Select Use for Controller Connections and Use for Application Reachability Probes, as required for this selected circuit category.Click Update.Configure VPN Keep-Alives for Circuits
- SelectWorkflowsSites/Data CentersSelect a SiteConfiguration.Click Change Circuits for either Internet Circuits or Private WAN Circuits.Click Edit below the circuit.In VPN Configs, for Keep-Alive Fail Count, enter a value between 3 and 30.The Keep-Alive Fail Count indicates the number of consecutive missed keep-alive packets before a link is declared as down. The default value is 3.
- For Keep-Alive Interval, enter a value between 100 ms and 600000 ms.The Keep-Alive Interval indicates the time interval in milliseconds between two VPN keep-alive packets. The default value is 1000 ms.Select the Override VPN Keep-Alive check box to use the VPN keep-alive values configured on the Circuit Information screen.When you select the Override VPN Keep-Alive check box, it implies that VPN keep-alive values configured for circuits are considered, and values configured for circuit categories are ignored.For Controller Connections and Application Reachability Probes, select Yes, No, or Use Circuit Category Setting from the drop-down.Click Done.
Configure VPN Keep-Alives for Secure Fabric Links
- From Map, select a branch site and click Overlay Connections.Select an overlay from either Branch-DC, or Branch-Branch.On Secure Fabric Link screen, click the edit icon and select the Enable VPN Configs check box.For Keep-Alive Failure Count, enter a value between 3 and 30.The keep-alive failure count indicates the number of consecutive missed keep-alive packets before a link is declared as down. The default value is 3.For Keep-Alive Interval, enter a value between 100 ms and 600000 ms.The keep-alive interval indicates the time interval in milliseconds between two VPN keep-alive packets. The default value is 1000 ms.Click Save.