08-27-2019 01:08 PM - edited 02-21-2020 09:25 AM
In regards to IPSEC tunnels, is it best to match PFS groups on the peer devices?
Solved! Go to Solution.
08-27-2019 01:11 PM
08-28-2019 06:40 AM
As RJI mentions, it should match/mirror on both sides. But it does not have to.
That means the PFS group is negotiated, but only to the minimum that is configured on the responder side.
08-27-2019 01:11 PM
08-27-2019 01:13 PM
08-27-2019 01:14 PM
02-24-2022 06:44 AM
I had an issue with mismatched PFS settings yesterday......here's what happened in my case. Phase 1 and phase 2 completed and the tunnel was up. However, only the first device trying to send traffic through the tunnel was able to communicate. Communication from all other devices failed. It didn't matter which device was the first to initiate traffic, the device that initiated traffic was the only one that could communicate through the tunnel.......communication from all other devices would fail.
08-28-2019 06:40 AM
As RJI mentions, it should match/mirror on both sides. But it does not have to.
That means the PFS group is negotiated, but only to the minimum that is configured on the responder side.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide