Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More

Anypoint VPN Tunnel Disruption due to Customer Gateway Dead Peer Detection (DPD) Timeout

Publish Date: Jul 8, 2026
Description

You observe DNS resolution failures or connection timeouts when applications attempt to communicate with internal resources (e.g., a DLB, private services) via an Anypoint VPN tunnel. This occurs during periods when the VPN tunnel experiences disruptions.

Resolution

CAUSE

The Anypoint VPN tunnel experiences disruptions because your Customer Gateway (CGW) fails to respond to Dead Peer Detection (DPD) keepalive requests sent by the MuleSoft VPN endpoint. This unresponsiveness leads to the VPN tunnel being marked as down, preventing network traffic, including DNS queries and application connections, from traversing the tunnel. Application-layer symptoms like DNS failures and connection drops are observed shortly after the underlying IKE-layer tunnel events.

SOLUTION

1.  **Review Customer Gateway Logs:** During the timeframe of the observed disruptions, review the logs of your Customer Gateway (CGW) device. Look for any indications of network instability, errors related to VPN tunnel negotiation, or DPD failures.
2.  **Investigate CGW Responsiveness:** Determine why your CGW is failing to respond to Dead Peer Detection (DPD) keepalive requests from the Anypoint VPN endpoint. Common causes include:
    *   Network instability or packet loss on your network path to the MuleSoft VPN endpoint.
    *   Misconfiguration of DPD settings on your CGW, such as incorrect DPD interval or action.
    *   Resource exhaustion or software/hardware issues on the CGW device itself.
3.  **Consult Network Team/VPN Provider:** Engage your internal network team or external VPN provider to diagnose and rectify the CGW's unresponsiveness.
4.  **Verify DPD Configuration:** Ensure that DPD settings on your CGW are correctly configured to respond to keepalive requests from the Anypoint VPN endpoint. Refer to your CGW vendor's documentation for specific DPD configuration parameters.

APPLIES TO

*   Anypoint VPN

Knowledge Article Number

005388673

 
Loading
Salesforce Help | Article