> Before 6.7 iked didn't start DPD in this particular case. > It kicks in if the tunnel is up and there haven't been any incoming ESP > packets > in the last 5 minutes. > A possible workaround would be to ping through the tunnel to have at least one > incoming packet every 5 minutes.
There is definitely ESP packets continuously, as there are 3-8 RDP sessions in this tunnel during workhours. That's why it's a problem, people get their RDP session disconnected every 8 minutes.

