Diffie-Hellman (DH) allows two devices to establish a shared secret over an unsecure network. In terms of VPN it is used in the in IKE or Phase1 part of setting up the VPN tunnel.
There are multiple Diffie-Hellman Groups that can be configured in an IKEv2 policy on a Cisco ASA running 9.1(3). In Nov 2016 ASA 9.6(x) is available and there are no new changes to the DH Groups.
Diffie-Hellman group 1 - 768 bit modulus - AVOID
Diffie-Hellman group 2 - 1024 bit modulus - AVOID
Diffie-Hellman group 5 - 1536 bit modulus - AVOID
Diffie-Hellman group 14 - 2048 bit modulus – MINIMUM ACCEPTABLE
Diffie-Hellman group 19 - 256 bit elliptic curve – ACCEPTABLE
Diffie-Hellman group 20 - 384 bit elliptic curve – Next Generation Encryption
Diffie-Hellman group 21 - 521 bit elliptic curve – Next Generation Encryption
Diffie-Hellman group 24 - modular exponentiation group with a 2048-bit modulus and 256-bit prime order subgroup – Next Generation Encryption
Algorithms marked as AVOID do not provide an adequate security level against modern threats and should not be used to protect sensitive information. It is recommended that these algorithms be replaced with stronger algorithms.
Next Generation Encryption (NGE) is expected to meet the security and scalability requirements of the next two decades.
If you are using encryption or authentication algorithms with a 128-bit key, use Diffie-Hellman groups 5, 14, 19, 20 or 24. If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21 or 24.
I have problem with Cisco ASA 5525-X. I can connect only via console port.From the CLI, I see all interfaces are shutdown.But I unable to set command no shutdown. Please help me to find command to enable the interfaces and set IP address to them.The ...
===Goal===Port forward inbound HTTPS requests on TCP-4434 on the outside interface and translate it to TCP-443 as it is sent to a webserver===Issue===When trying to reach the web server using https://[outside IP address]:4434 in Firefox, I am automaticall...
Hi everybody. I´ve configured this lab and an access-list on the firewall but I can´t access the server from outside. I'm trying to figure this out but I can't seem to get it.I´ve attached the lab in zip file if someone ...
Hi everyone ,we are using cisco ISE 2.7 in our network for Guest portal page authentication with self registration for wireless users and everything works fine,Since one week ago we have tested the Ver 3.1 to migrate from 2.7 to Ver 3.1 with same sc...