VPN Keep-Alives
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Prisma SD-WAN Clarity Reports
- Prisma SD-WAN Incidents and Alerts
VPN Keep-Alives
VPN keep-alive packets determine whether a given path is reachable for an Prisma SD-WAN.
You can configure VPN Keep-Alives for circuit categories, circuits, and Secure Fabric
Links.
Where Can I Use
This? | What Do I
Need? |
---|---|
|
|
VPN keep-alive packets determine whether a given path is reachable for
an ION device. VPN keep-alive packets are sent at a fixed interval on a VPN link.
The VPN link is declared down, if the peer is unreachable after a certain number of
attempts and a certain period of time.
The location of the ION device in a network topology plays an important role in
configuring VPN keep-alives. For example, you need to configure a higher value of
the keep-alive Interval between two ION devices behind routers as compared to the
keep-alive Interval between two ION devices not behind routers.
VPN keep-alives are configured at the following levels:
The order of precedence for VPN keep-alives is as follows:
- VPN keep-alives configured at the secure fabric link level have the highest priority.
- If VPN keep-alives are not configured at the secure fabric link level, then VPN keep-alives configured at the circuits level take effect.
- If VPN keep-alives are not configured at both secure fabric link level and circuits level, then VPN keep-alives configured at the circuit categories level take effect.
If there is a mismatch in configuration between two VPN endpoints, then:
- The keep-alive configuration with the larger keep-alive interval takes effect.
- If keep-alive intervals are the same, then the configuration with the higher keep-alive failure count takes effect.
Configure VPN Keep-Alives for Circuit Categories
For metered links, where there is a cost for usage (such as LTE interfaces), VPN
keep-alives can be adjusted to minimize the usage of the link and any costs
associated with using the link. VPN keep-alives can also be modified for
unreliable circuits that experience high latency and loss such as
satellites.
- SelectManage,Resources, and then selectCircuit Categories.
- Edit a circuit category and enter values forKeep-Alive Failure CountandKeep-Alive Interval.
- ForKeep-Alive Failure Count, enter a value between 3 and 30.TheKeep-Alive Failure Countindicates the number of consecutive missed keep-alive packets before a link is declared as down. The default value is 3.
- ForKeep-Alive Interval, enter a value between 100 ms and 600000 ms.TheKeep-Alive Intervalindicates the time interval in milliseconds between two VPN keep-alive packets. The default value is1000 ms.
- SelectUse for Controller ConnectionsandUse for Application Reachability Probes, as required for this selected circuit category.
- ClickUpdate.
Configure VPN Keep-Alives for Circuits
- Select.WorkflowsSites/Data CentersSelect a SiteConfiguration
- ClickChange Circuitsfor eitherInternet CircuitsorPrivate WAN Circuits.
- ClickEditbelow the circuit.
- In VPN Configs, forKeep-Alive Fail Count, enter a value between 3 and 30.The Keep-Alive Fail Count indicates the number of consecutive missed keep-alive packets before a link is declared as down. The default value is 3.
- ForKeep-Alive Interval, enter a value between 100 ms and 600000 ms.The Keep-Alive Interval indicates the time interval in milliseconds between two VPN keep-alive packets. The default value is 1000 ms.
- Select theOverride VPN Keep-Alivecheck box to use the VPN keep-alive values configured on theCircuit Informationscreen.When you select theOverride VPN Keep-Alivecheck box, it implies that VPN keep-alive values configured for circuits are considered, and values configured for circuit categories are ignored.
- ForController ConnectionsandApplication Reachability Probes, selectYes,No, orUse Circuit Category Settingfrom the drop-down.
- ClickDone.
Configure VPN Keep-Alives for Secure Fabric Links
- FromMap, select a branch site and clickOverlay Connections.
- Select an overlay from eitherBranch-DC, orBranch-Branch.
- OnSecure Fabric Linkscreen, click the edit icon and select theEnable VPN Configscheck box.
- ForKeep-Alive Failure Count, enter a value between 3 and 30.The keep-alive failure count indicates the number of consecutive missed keep-alive packets before a link is declared as down. The default value is 3.
- ForKeep-Alive Interval, enter a value between 100 ms and 600000 ms.The keep-alive interval indicates the time interval in milliseconds between two VPN keep-alive packets. The default value is 1000 ms.
- ClickSave.