10-13-2023 02:49 AM
Hello everybody,
our customer has a Firepower 4110 running ASA OS image 9.16(4)14 with
56 2S2-tunnels configured (configuration attached).
They want to upgrade to the current suggested release 9.18(3) and expect
problems because many of the 2S2-tunnels are IKEv1.
Is there a document that describe the differences between the releases
9.16(4)14 and 9.18(3) regarding 2S2-tunnels?
Or is there a tool that can ckeck the configuration to incompatibilities with
the new release 9.18(3)?
Every hint is very welcome!
Thanks a lot!
Bye
R.
Solved! Go to Solution.
10-13-2023 03:03 AM
@swscco001 In 9.13 the older weaker ciphers were depreciated and removed in 9.15. I can also see from your configuration the IKE policies may be called DES, 3DES but actually the configured proposals are AES.
I do note you have PFS group 5 configured which has been depreciated, remove or change this.
You should refer to the release notes for 9.17, 9.18 to determine if anything specific relates to your configuration.
10-13-2023 02:56 AM
Only check phase2 proposal different' I think MD5 is weak and remove and some sha 128 is also remove.
Also DH group is different between two ver.
Other feature is same between 9.16 and 9.18 for s2s vpn.
10-13-2023 03:10 AM
I check release notes there is no alot info. About dh group and weak remove form 9.18
But I share links about vpn s2s for 9.18 and 9.16 in which you can learn more about these points.
10-13-2023 03:03 AM
@swscco001 In 9.13 the older weaker ciphers were depreciated and removed in 9.15. I can also see from your configuration the IKE policies may be called DES, 3DES but actually the configured proposals are AES.
I do note you have PFS group 5 configured which has been depreciated, remove or change this.
You should refer to the release notes for 9.17, 9.18 to determine if anything specific relates to your configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide