12-07-2016 06:38 AM - edited 03-12-2019 01:38 AM
Hi,
In router for the PFS, default group is 1.. How about in ASA firewall, which group is default for the PFS.
12-13-2016 11:14 AM
Hi Santhosh,
The ASA uses PFS as an optional command - I do not believe there is a default.
You can type "show run all" to see all hidden and default commands on the ASA
Here is a link about IPSEC
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119141-configure-asa-00.html
12-13-2016 10:49 PM
PFS uses DH policy of 1,2,5.. Just wanted to know, If we give just set pfs, which default DH policy it will take up.
12-13-2016 06:28 PM
hi,
PFS in ASA (for IKE phase 2) is disabled by default.
you just manually choose which DH group to use for PFS.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide