<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DH group24 (phase I)and  set pfs group24 (phase II) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604135#M1089792</link>
    <description>&lt;P&gt;Thanks I don't think it is a NAT issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It happens with a lot tunnels of our vendors.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There some tunnels I control both ends still have the issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2022 01:28:17 GMT</pubDate>
    <dc:creator>loc.nguyen</dc:creator>
    <dc:date>2022-05-04T01:28:17Z</dc:date>
    <item>
      <title>DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604048#M1089778</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We still have some VPN site to site tunnels use group24. DH group24 (phase I)and set pfs group24 (phase II)&lt;/P&gt;&lt;P&gt;I know we should move to group14, but for some reasons we could change it right way,&lt;/P&gt;&lt;P&gt;I feel like using group24 cause a lot of unexpected issue between both ends of the tunnel. (We need to reset the tunnel to fix it)&lt;/P&gt;&lt;P&gt;Beside the security risk of using group24, will we have preferment issue ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Loc&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 20:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604048#M1089778</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-03T20:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604051#M1089779</link>
      <description>&lt;P&gt;Not that aware you have issue, is both the side cisco ? what device is this ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 21:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604051#M1089779</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-05-03T21:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604052#M1089780</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1201337"&gt;@loc.nguyen&lt;/a&gt; not sure I fully understand your question.&lt;/P&gt;
&lt;P&gt;You can specify multiple DH groups and specify an order, the peers will use the first mutual match.&lt;/P&gt;
&lt;P&gt;DH group 24 has been depreciated in newer software versions, Cisco recommends DH group 19, 20.&lt;/P&gt;
&lt;P&gt;Here is the Cisco Next Gen Encryption (NGE) guide for reference &lt;A href="https://tools.cisco.com/security/center/resources/next_generation_cryptography#4" target="_blank"&gt;https://tools.cisco.com/security/center/resources/next_generation_cryptography&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 21:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604052#M1089780</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-03T21:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604060#M1089781</link>
      <description>&lt;P&gt;Do you know if DH group 24 cause performance issue ?&lt;/P&gt;&lt;P&gt;Or it is just a security concern to use it?&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 21:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604060#M1089781</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-03T21:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604067#M1089782</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1201337"&gt;@loc.nguyen&lt;/a&gt; it's definately weak and best avoided.&lt;/P&gt;
&lt;P&gt;What performance issues do you experience?&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 21:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604067#M1089782</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-03T21:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604069#M1089783</link>
      <description>&lt;P&gt;I don't think the DH group make tunnel stuck there is something elsa,&lt;BR /&gt;can you share config of ASA ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if am right and recording to your previous post, and as I mention to check it,&amp;nbsp;&lt;BR /&gt;the remote is recently add NAT device in between, and this make tunnel stuck and need to reset after work for a hours.&amp;nbsp;&lt;BR /&gt;contact the remote ask him the IP and adjust the config to add new remote-id.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 21:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604069#M1089783</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-03T21:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604133#M1089791</link>
      <description>&lt;P&gt;The tunnel is freeze. It was stuck when it rekey or renegotiate the parameters I think. We need to reset it to make it works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 01:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604133#M1089791</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-04T01:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604135#M1089792</link>
      <description>&lt;P&gt;Thanks I don't think it is a NAT issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It happens with a lot tunnels of our vendors.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There some tunnels I control both ends still have the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 01:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604135#M1089792</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-04T01:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604139#M1089793</link>
      <description>&lt;P&gt;You Are right If you control both end then DH group mismatch in PhaseII rekey is make tunnel stuck.&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POf1CAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POf1CAG&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.juniper.net/communities/community-home/digestviewer/viewthread?MID=72612" target="_blank"&gt;https://community.juniper.net/communities/community-home/digestviewer/viewthread?MID=72612&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;two vendor same issue with DH group.&amp;nbsp;&lt;BR /&gt;recommend to match the DH group in Phase I and Phase II.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 01:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604139#M1089793</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-04T01:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604145#M1089794</link>
      <description>&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 02:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604145#M1089794</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-04T02:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604497#M1089809</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1201337"&gt;@loc.nguyen&lt;/a&gt; which version, IKEv1 or IKEv2? &lt;/P&gt;
&lt;P&gt;Which platform ASA, FTD or IOS?&lt;/P&gt;
&lt;P&gt;If using IKEv1 check your lifetime timers are the same on both peers.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 15:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4604497#M1089809</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-04T15:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605146#M1089836</link>
      <description>&lt;P&gt;We use IKEv2 only.&lt;/P&gt;&lt;P&gt;It happens all platform ASA and FTD and Checkpoint.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 15:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605146#M1089836</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-05T15:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605176#M1089838</link>
      <description>&lt;P&gt;you mean that the two peers is ASA or ASA-FTD or ASA/FTD-Checkpoint ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 15:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605176#M1089838</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-05T15:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605187#M1089839</link>
      <description>&lt;P&gt;All of them, but the issue happens the most on the pair&amp;nbsp;&lt;SPAN&gt;FTD-Checkpoint&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605187#M1089839</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-05T16:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: DH group24 (phase I)and  set pfs group24 (phase II)</title>
      <link>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605197#M1089840</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122438" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122438&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dh-group24-phase-i-and-set-pfs-group24-phase-ii/m-p/4605197#M1089840</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-05T16:08:13Z</dc:date>
    </item>
  </channel>
</rss>

