cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4701
Views
25
Helpful
2
Replies

diffie-hellman groups supports in version 6.7

support040
Level 1
Level 1

Hi,

I need a simple Answer please ...

all release Notes tells us some DH groups not supported in FTD version 6.7

 

 

Please give me a simple answer:

 

WHICH DH groups WILL support in FTD version 6.7 for IKE v1 and V2 for Phase 1 and 2 ????

 

thanks for your clear answer 

Ashkan

2 Accepted Solutions

Accepted Solutions

@support040 

The following DH groups are supported from FTD 6.7:- 14,15, 16, 19, 20 and 21

FTD 6.7 removed support for:- 2, 5 and 25

 

HTH

View solution in original post

Marvin Rhoads
Hall of Fame
Hall of Fame

So...

"If you are still using these features in IKE proposals or IPsec policies, change and verify your VPN configuration before you upgrade."

If you don't do that, the upgrade will break them.

Note that ASA 9.15 similarly removes support for DH groups 2 and 24 (as well as some less-secure encryption algorithms and hashes).

https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/release/notes/asarn915.html#id_25471

View solution in original post

2 Replies 2

@support040 

The following DH groups are supported from FTD 6.7:- 14,15, 16, 19, 20 and 21

FTD 6.7 removed support for:- 2, 5 and 25

 

HTH

Marvin Rhoads
Hall of Fame
Hall of Fame

So...

"If you are still using these features in IKE proposals or IPsec policies, change and verify your VPN configuration before you upgrade."

If you don't do that, the upgrade will break them.

Note that ASA 9.15 similarly removes support for DH groups 2 and 24 (as well as some less-secure encryption algorithms and hashes).

https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/release/notes/asarn915.html#id_25471

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card