<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA does not have the ability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010275#M134547</link>
    <description>&lt;P&gt;ASA does not have the ability to do DH group 14 with IKEv1, you would need to use IKEv2 to do this. There is an open enhancement request for this capability:&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuv51888/?referring_site=bugquickviewredir&lt;/P&gt;
&lt;P&gt;You would have to use the next best option: DH group 5, if you have to use IKEv1.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2017 17:46:09 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2017-06-22T17:46:09Z</dc:date>
    <item>
      <title>Can Diffie-Hellman Group 14 be configured on ASA5520, v9.1(6)11</title>
      <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010274#M134546</link>
      <description>&lt;P&gt;I am creating a VPN between an ASA and a&amp;nbsp;Juniper SRX, using IKEv1. The owner of the&amp;nbsp;Juniper SRX is asking for DH group 14. I only see how to configure DH group 5 using the ASA ASDM.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How does one configure DH group 14 on the ASA?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010274#M134546</guid>
      <dc:creator>scottsassin</dc:creator>
      <dc:date>2019-03-12T09:37:17Z</dc:date>
    </item>
    <item>
      <title>ASA does not have the ability</title>
      <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010275#M134547</link>
      <description>&lt;P&gt;ASA does not have the ability to do DH group 14 with IKEv1, you would need to use IKEv2 to do this. There is an open enhancement request for this capability:&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuv51888/?referring_site=bugquickviewredir&lt;/P&gt;
&lt;P&gt;You would have to use the next best option: DH group 5, if you have to use IKEv1.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 17:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010275#M134547</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-06-22T17:46:09Z</dc:date>
    </item>
    <item>
      <title>How does one configure ikev2</title>
      <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010276#M134548</link>
      <description>&lt;P&gt;How does one configure ikev2 with DH14? I still only see 1,2,5 as choices.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 19:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010276#M134548</guid>
      <dc:creator>scottsassin</dc:creator>
      <dc:date>2017-06-22T19:25:07Z</dc:date>
    </item>
    <item>
      <title>You should use the ikev2</title>
      <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010277#M134549</link>
      <description>&lt;P&gt;You should use the ikev2 policy command:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;crypto ikev2 policy 100&lt;BR /&gt; encryption aes&lt;BR /&gt; integrity sha&lt;BR /&gt;&lt;STRONG&gt; group 14&lt;/STRONG&gt;&lt;BR /&gt; prf sha&lt;BR /&gt; lifetime seconds 86400&lt;/PRE&gt;
&lt;P&gt;According to the command reference, you should be able to add Group 14 from 9.0(1) onwards:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/gh.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 19:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010277#M134549</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-06-22T19:44:14Z</dc:date>
    </item>
    <item>
      <title>Can I also add DH-group 14</title>
      <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010278#M134550</link>
      <description>&lt;P&gt;Can I also add DH-group 14 for Perfect Forward Secrecy?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 19:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010278#M134550</guid>
      <dc:creator>scottsassin</dc:creator>
      <dc:date>2017-06-22T19:59:22Z</dc:date>
    </item>
    <item>
      <title>Sure you can. Command is:</title>
      <link>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010279#M134551</link>
      <description>&lt;P&gt;Sure you can. Command is:&lt;/P&gt;
&lt;PRE class="pEx1_Example1 prettyprint"&gt;&lt;SPAN&gt;&lt;B class="cBold"&gt;crypto map &amp;lt;map_name&amp;gt; &amp;lt;map_index&amp;gt; set pfs [group1 | group2 | group5 | group14 | group19 | group20 | group21 | group24]&lt;BR /&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Reference:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/vpn_ike.html&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 20:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-diffie-hellman-group-14-be-configured-on-asa5520-v9-1-6-11/m-p/3010279#M134551</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-06-22T20:08:46Z</dc:date>
    </item>
  </channel>
</rss>

