05-03-2022 01:57 PM
Hi,
We still have some VPN site to site tunnels use group24. DH group24 (phase I)and set pfs group24 (phase II)
I know we should move to group14, but for some reasons we could change it right way,
I feel like using group24 cause a lot of unexpected issue between both ends of the tunnel. (We need to reset the tunnel to fix it)
Beside the security risk of using group24, will we have preferment issue ?
Thanks
Loc
Solved! Go to Solution.
05-03-2022 06:44 PM - edited 05-03-2022 06:55 PM
You Are right If you control both end then DH group mismatch in PhaseII rekey is make tunnel stuck.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POf1CAG
https://community.juniper.net/communities/community-home/digestviewer/viewthread?MID=72612
two vendor same issue with DH group.
recommend to match the DH group in Phase I and Phase II.
05-03-2022 02:04 PM
Not that aware you have issue, is both the side cisco ? what device is this ?
05-03-2022 02:07 PM
@loc.nguyen not sure I fully understand your question.
You can specify multiple DH groups and specify an order, the peers will use the first mutual match.
DH group 24 has been depreciated in newer software versions, Cisco recommends DH group 19, 20.
Here is the Cisco Next Gen Encryption (NGE) guide for reference https://tools.cisco.com/security/center/resources/next_generation_cryptography
05-03-2022 02:26 PM
Do you know if DH group 24 cause performance issue ?
Or it is just a security concern to use it?
05-03-2022 02:46 PM
@loc.nguyen it's definately weak and best avoided.
What performance issues do you experience?
05-03-2022 06:26 PM - edited 05-03-2022 06:26 PM
The tunnel is freeze. It was stuck when it rekey or renegotiate the parameters I think. We need to reset it to make it works.
05-04-2022 08:20 AM
@loc.nguyen which version, IKEv1 or IKEv2?
Which platform ASA, FTD or IOS?
If using IKEv1 check your lifetime timers are the same on both peers.
05-05-2022 08:13 AM
We use IKEv2 only.
It happens all platform ASA and FTD and Checkpoint.
05-05-2022 08:47 AM
you mean that the two peers is ASA or ASA-FTD or ASA/FTD-Checkpoint ?
05-05-2022 09:00 AM
All of them, but the issue happens the most on the pair FTD-Checkpoint
05-05-2022 09:08 AM
05-03-2022 02:47 PM
I don't think the DH group make tunnel stuck there is something elsa,
can you share config of ASA ?
if am right and recording to your previous post, and as I mention to check it,
the remote is recently add NAT device in between, and this make tunnel stuck and need to reset after work for a hours.
contact the remote ask him the IP and adjust the config to add new remote-id.
05-03-2022 06:28 PM
Thanks I don't think it is a NAT issue.
It happens with a lot tunnels of our vendors.
There some tunnels I control both ends still have the issue.
05-03-2022 06:44 PM - edited 05-03-2022 06:55 PM
You Are right If you control both end then DH group mismatch in PhaseII rekey is make tunnel stuck.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POf1CAG
https://community.juniper.net/communities/community-home/digestviewer/viewthread?MID=72612
two vendor same issue with DH group.
recommend to match the DH group in Phase I and Phase II.
05-03-2022 07:37 PM
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide