A Site-to-Site VPN shows IKE sessions ending when application connectivity fails. What action should the network engineer take so that if the IKE session goes down it will come back up?
Choose an answer
Tap an option to check your answer.
Correct answer: Set the dead peer detection (DPD) timeout action to Restart. Initiate traffic from on premises to the VPC..
Why this is the answer
The correct action is to set the Dead Peer Detection (DPD) timeout action to Restart and initiate traffic from on-premises to the VPC. When DPD is set to Restart, the VPN tunnel will automatically attempt to re-establish the IKE session if it detects that the peer is unresponsive. Initiating traffic from the on-premises network (the customer gateway side) is crucial because it often triggers the re-negotiation of the IKE and IPsec SAs, bringing the tunnel back up. Setting DPD to Clear or None would not automatically re-establish the tunnel; Clear would remove the session without restarting, and None would disable DPD. Cancel is not a standard DPD timeout action. While initiating traffic from the VPC side might sometimes help, the on-premises side is typically where the customer gateway resides, and initiating traffic from there is a more reliable way to prompt tunnel re-establishment after a DPD restart.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed