cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5120
Views
30
Helpful
5
Replies

IPSEC Tunnel PFS Groups need to match?

CiscoPurpleBelt
Level 6
Level 6

In regards to IPSEC tunnels, is it best to match PFS groups on the peer devices?

2 Accepted Solutions

Accepted Solutions

Hi,
Yes, all attributes must match/mirror each other on the devices when establishing a VPN.
PFS is also optional.

HTH

View solution in original post

As RJI mentions, it should match/mirror on both sides. But it does not have to.

  • If the initiator does not have PFS configured or a smaller group than the responder, the connection will fail.
  • If the initiator has a group configured but the responder does not, or the responder has a smaller group configured, then the PFS-group of the initiator is used.

That means the PFS group is negotiated, but only to the minimum that is configured on the responder side.

View solution in original post

5 Replies 5

Hi,
Yes, all attributes must match/mirror each other on the devices when establishing a VPN.
PFS is also optional.

HTH

Tunnel is up with different PFS groups, however not sure if it causes problems.

Hmmm, can you provide the output of "show crypto ipsec sa detail" from both devices?

I had an issue with mismatched PFS settings yesterday......here's what happened in my case. Phase 1 and phase 2 completed and the tunnel was up. However, only the first device trying to send traffic through the tunnel was able to communicate. Communication from all other devices failed. It didn't matter which device was the first to initiate traffic, the device that initiated traffic was the only one that could communicate through the tunnel.......communication from all other devices would fail.

As RJI mentions, it should match/mirror on both sides. But it does not have to.

  • If the initiator does not have PFS configured or a smaller group than the responder, the connection will fail.
  • If the initiator has a group configured but the responder does not, or the responder has a smaller group configured, then the PFS-group of the initiator is used.

That means the PFS group is negotiated, but only to the minimum that is configured on the responder side.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card