01-28-2021 05:13 AM
Hi,
I need a simple Answer please ...
all release Notes tells us some DH groups not supported in FTD version 6.7
Please give me a simple answer:
WHICH DH groups WILL support in FTD version 6.7 for IKE v1 and V2 for Phase 1 and 2 ????
thanks for your clear answer
Ashkan
Solved! Go to Solution.
01-28-2021 05:19 AM
The following DH groups are supported from FTD 6.7:- 14,15, 16, 19, 20 and 21
FTD 6.7 removed support for:- 2, 5 and 25
HTH
01-28-2021 05:47 AM
So...
"If you are still using these features in IKE proposals or IPsec policies, change and verify your VPN configuration before you upgrade."
If you don't do that, the upgrade will break them.
Note that ASA 9.15 similarly removes support for DH groups 2 and 24 (as well as some less-secure encryption algorithms and hashes).
https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/release/notes/asarn915.html#id_25471
01-28-2021 05:19 AM
The following DH groups are supported from FTD 6.7:- 14,15, 16, 19, 20 and 21
FTD 6.7 removed support for:- 2, 5 and 25
HTH
01-28-2021 05:47 AM
So...
"If you are still using these features in IKE proposals or IPsec policies, change and verify your VPN configuration before you upgrade."
If you don't do that, the upgrade will break them.
Note that ASA 9.15 similarly removes support for DH groups 2 and 24 (as well as some less-secure encryption algorithms and hashes).
https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/release/notes/asarn915.html#id_25471
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide