<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC Tunnel PFS Groups need to match? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914969#M5674</link>
    <description>Hmmm, can you provide the output of "show crypto ipsec sa detail" from both devices?</description>
    <pubDate>Tue, 27 Aug 2019 20:14:38 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-08-27T20:14:38Z</dc:date>
    <item>
      <title>IPSEC Tunnel PFS Groups need to match?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914964#M5671</link>
      <description>&lt;P&gt;In regards to IPSEC tunnels, is it best to match PFS groups on the peer devices?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914964#M5671</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2020-02-21T17:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel PFS Groups need to match?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914966#M5672</link>
      <description>Hi,&lt;BR /&gt;Yes, all attributes must match/mirror each other on the devices when establishing a VPN. &lt;BR /&gt;PFS is also optional.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 27 Aug 2019 20:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914966#M5672</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-08-27T20:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel PFS Groups need to match?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914968#M5673</link>
      <description>Tunnel is up with different PFS groups, however not sure if it causes problems.</description>
      <pubDate>Tue, 27 Aug 2019 20:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914968#M5673</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-08-27T20:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel PFS Groups need to match?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914969#M5674</link>
      <description>Hmmm, can you provide the output of "show crypto ipsec sa detail" from both devices?</description>
      <pubDate>Tue, 27 Aug 2019 20:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3914969#M5674</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-08-27T20:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel PFS Groups need to match?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3915343#M5675</link>
      <description>&lt;P&gt;As RJI mentions, it should&amp;nbsp;match/mirror on both sides. But it does not have to.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If the initiator does not have PFS configured or a smaller group&amp;nbsp;than the responder, the connection will fail.&lt;/LI&gt;
&lt;LI&gt;If the initiator has a group configured but the responder does&amp;nbsp;not, or the responder has a smaller group configured, then the PFS-group of the initiator is used.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;That means the PFS group is negotiated, but only to the minimum that is configured on the responder side.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 13:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/3915343#M5675</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2019-08-28T13:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel PFS Groups need to match?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/4558910#M1087647</link>
      <description>&lt;P&gt;I had an issue with mismatched PFS settings yesterday......here's what happened in my case. Phase 1 and phase 2 completed and the tunnel was up. However, only the first device trying to send traffic through the tunnel was able to communicate. Communication from all other devices failed. It didn't matter which device was the first to initiate traffic, the device that initiated traffic was the only one that could communicate through the tunnel.......communication from all other devices would fail.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 14:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-pfs-groups-need-to-match/m-p/4558910#M1087647</guid>
      <dc:creator>desktopAdmin</dc:creator>
      <dc:date>2022-02-24T14:44:22Z</dc:date>
    </item>
  </channel>
</rss>

