cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3326
Views
1
Helpful
3
Replies

Perfect Forward Secrecy (PFS)

Santhosh PS
Level 1
Level 1

Hi,

In router for the PFS, default group is 1.. How about in ASA firewall, which group is default for the PFS.

3 Replies 3

John Forester
Level 1
Level 1

Hi Santhosh,

The ASA uses PFS as an optional command - I do not believe there is a default.

You can type "show run all" to see all hidden and default commands on the ASA

Here is a link about IPSEC

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119141-configure-asa-00.html

PFS uses DH policy of 1,2,5.. Just wanted to know, If we give just set pfs, which default DH policy it will take up.

johnlloyd_13
Level 9
Level 9

hi,

PFS in ASA (for IKE phase 2) is disabled by default.

you just manually choose which DH group to use for PFS.

Review Cisco Networking for a $25 gift card