<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5506 - Unable to set DH Group 20 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899372#M161670</link>
    <description>&lt;P&gt;Hi. I'm having a really weird issue on an ASA 5506 firewall where i'm trying to use DH Group20 on a VPN tunnel. For some odd reason on my crypto map it only gives me the option to set groups 1,2, or 5. But if I were to change the name of the crypto map, I then have the option to set all the other groups.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-5506(config)# crypto map &lt;STRONG&gt;CRYPTO-MAP1&lt;/STRONG&gt; 10 set pfs ?&lt;/P&gt;
&lt;P&gt;configure mode commands/options:&lt;BR /&gt; group1 D-H Group 1&lt;BR /&gt; group2 D-H Group 2&lt;BR /&gt; group5 D-H Group 5&lt;BR /&gt; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA-5506(config)# crypto map &lt;STRONG&gt;CRYPTO-MAP-2&lt;/STRONG&gt; 10 set pfs ?&lt;/P&gt;
&lt;P&gt;configure mode commands/options:&lt;BR /&gt; group1 D-H Group 1&lt;BR /&gt; group14 D-H Group 14 (Unsupported for IKEv1)&lt;BR /&gt; group19 D-H Group 19 (Unsupported for IKEv1)&lt;BR /&gt; group2 D-H Group 2&lt;BR /&gt; group20 D-H Group 20 (Unsupported for IKEv1)&lt;BR /&gt; group21 D-H Group 21 (Unsupported for IKEv1)&lt;BR /&gt; group24 D-H Group 24 (Unsupported for IKEv1)&lt;BR /&gt; group5 D-H Group 5&lt;BR /&gt; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA-5506(config)#&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:52:05 GMT</pubDate>
    <dc:creator>Charger1129</dc:creator>
    <dc:date>2019-03-12T07:52:05Z</dc:date>
    <item>
      <title>ASA 5506 - Unable to set DH Group 20</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899372#M161670</link>
      <description>&lt;P&gt;Hi. I'm having a really weird issue on an ASA 5506 firewall where i'm trying to use DH Group20 on a VPN tunnel. For some odd reason on my crypto map it only gives me the option to set groups 1,2, or 5. But if I were to change the name of the crypto map, I then have the option to set all the other groups.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-5506(config)# crypto map &lt;STRONG&gt;CRYPTO-MAP1&lt;/STRONG&gt; 10 set pfs ?&lt;/P&gt;
&lt;P&gt;configure mode commands/options:&lt;BR /&gt; group1 D-H Group 1&lt;BR /&gt; group2 D-H Group 2&lt;BR /&gt; group5 D-H Group 5&lt;BR /&gt; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA-5506(config)# crypto map &lt;STRONG&gt;CRYPTO-MAP-2&lt;/STRONG&gt; 10 set pfs ?&lt;/P&gt;
&lt;P&gt;configure mode commands/options:&lt;BR /&gt; group1 D-H Group 1&lt;BR /&gt; group14 D-H Group 14 (Unsupported for IKEv1)&lt;BR /&gt; group19 D-H Group 19 (Unsupported for IKEv1)&lt;BR /&gt; group2 D-H Group 2&lt;BR /&gt; group20 D-H Group 20 (Unsupported for IKEv1)&lt;BR /&gt; group21 D-H Group 21 (Unsupported for IKEv1)&lt;BR /&gt; group24 D-H Group 24 (Unsupported for IKEv1)&lt;BR /&gt; group5 D-H Group 5&lt;BR /&gt; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA-5506(config)#&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899372#M161670</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2019-03-12T07:52:05Z</dc:date>
    </item>
    <item>
      <title>This behavior is shown if the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899373#M161672</link>
      <description>&lt;P&gt;This behavior is shown if the crypto map sequence is already in use with a peer that uses IKEv1. Is that the case for "CRYPTO-MAP1 10"? If you test it with the same crypto map but an unused sequence, then you should also see all DH-groups for PFS.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 09:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899373#M161672</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-06-14T09:58:47Z</dc:date>
    </item>
    <item>
      <title>Really appreciate the help!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899374#M161674</link>
      <description>&lt;P&gt;Really appreciate the help! you were exactly right. Once i removed the last line in bold I was good to go. I didn't realize I added that in there. Thanks again!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;crypto map CRYPTO-MAP 10 match address ACL_1_VPN_TUNNEL&lt;BR /&gt;crypto map CRYPTO-MAP 10 set pfs group5&lt;BR /&gt;crypto map CRYPTO-MAP 10 set peer REMOTE-ASA&lt;BR /&gt;&lt;STRONG&gt;crypto map CRYPTO-MAP 10 set ikev1 transform-set ESP-3DES-SHA-TRANS&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 14:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-unable-to-set-dh-group-20/m-p/2899374#M161674</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2016-06-14T14:07:56Z</dc:date>
    </item>
  </channel>
</rss>

