cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1863
Views
5
Helpful
4
Replies

FTD 6.5 and Diffie Hellman G5

benolyndav
Level 4
Level 4

HI

We have upgraded our soon to go live FTD's/FMC to 6.5 I have just seen a warning saying that DH group 5 is depreciated, does this mean that it just wont work as we have exsisting VPN's using DH group 5 on our current live devices ASA's

 

Thanks

2 Accepted Solutions

Accepted Solutions

Hi,
No, I am saying it will currently work on 6.5.....but at somepoint in the future cisco will remove DH group 5, so don't upgrade until you've changed your existing VPNs.

View solution in original post

4 Replies 4

Hi,
If you upgrade to a newer version once DH group 5 has been depreciated, at that point you will have a problem. You should probably change your existing VPNs now, as DH group 5 is insecure - also avoid DH group 2 and 24.

HTH

Hi Rob

Thanks for the quick response so are you saying DH 5 just wont work on 6.5 ??

Hi,
No, I am saying it will currently work on 6.5.....but at somepoint in the future cisco will remove DH group 5, so don't upgrade until you've changed your existing VPNs.

Thanks Rob

Review Cisco Networking for a $25 gift card