10-13-2023 05:20 AM
Hi guys,
I am asking you for help in activating my DH group 5
10-13-2023 05:42 AM
its been deprecated 6.7 onwards :
10-13-2023 05:54 AM
So also there is no other possibility of using version 1 or 2
10-13-2023 05:43 AM
- Its been flagged as depreciated , hence can no longer be activated ,
M.
10-13-2023 05:51 AM
So there is no way to activate it???
10-13-2023 05:58 AM
@Diallo even on 7.3 you can still select DH group 5 to use in an IKEv2 policy. Although I would strongly recommend not doing so, as it's likely this will shortly be removed from FTD altogether (it has already been removed from ASA). I recommend you reconfigure the peer configuration to use a stronger DH group (19,20 or 21 etc).
10-13-2023 06:17 AM
I just have to use it in the creation of a VPN with a partner who uses ASA and tells me that he only uses versions 1,2 and 5.
With its status there can it work???
10-13-2023 06:21 AM
@Diallo yes, but if you use DH group 5 (whilst it's still available to deploy) you will not be able to upgrade your FTD in future, as I already stated the weaker ciphers (including DH group 5) will be removed in upcoming releases. I would suggest the partner upgrades their software to support stronger crypto, the DH groups their software supports is weak and insecure.
10-13-2023 06:46 AM
@Rob Ingram thank you very much for your suggestions.
You are absolutely right, I will talk to the partner about updating their ASA if possible.
But in the meantime we are going to use group 5 there with its status like that.
10-13-2023 06:35 AM - edited 10-13-2023 06:36 AM
I had another customer's peer claim this as well. Often they are Just Wrong. ASA has supported IKEv2 with DH Group 14 since version 9.0 which is available even on the log-past-end-of-life ASA 5500 series (5505/5510/5520/5540/5550/5585).
10-13-2023 06:53 AM
@Marvin Rhoads thank you very much for your solution I see that this is possible with ASA5520 for group 14
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide