cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4644
Views
1
Helpful
3
Replies

Perfect Forward Secrecy (PFS)

Santhosh PS
Frequent Visitor
Frequent Visitor

Hi,

In router for the PFS, default group is 1.. How about in ASA firewall, which group is default for the PFS.

3 Replies 3

John Forester
Level 3
Level 3

Hi Santhosh,

The ASA uses PFS as an optional command - I do not believe there is a default.

You can type "show run all" to see all hidden and default commands on the ASA

Here is a link about IPSEC

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119141-configure-asa-00.html

PFS uses DH policy of 1,2,5.. Just wanted to know, If we give just set pfs, which default DH policy it will take up.

johnlloyd_13
Level 11
Level 11

hi,

PFS in ASA (for IKE phase 2) is disabled by default.

you just manually choose which DH group to use for PFS.

Review Cisco Networking for a $25 gift card