Recommendations
- Customers can initiate a tunnel termination when a traffic failure is detected via the primary.
- If initiating a tunnel termination is not feasible, the BGP session can be terminated or customers can wait for the BGP hold timer to expire.
- The DPD timeout for a customer org should be configured to match the Secure Access DPD timeout (156 seconds max). For example, 1 DPD every 30 seconds and 4 retransmits before failure; in other words, 30 secs * 5 DPD = 150 secs delay.