cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2495
Views
10
Helpful
17
Replies

FPR-2110, ASDM 7.14(1) , ASA 9.14(3) , IKEv1 Group-14 usable for PFS?

JVD66
Level 1
Level 1

Good day -

  I am trying to configure an FPR-2110, to follow instructions on connecting to an APN gateway,
  which specifies to use a VTI IPSEC with IKEv1 pre-shared key only with PFS enabled ,
  DH-Group-21 initially, which they kindly changed to DH-Group-14 for us, but now I find,
  though I can select on the Configuration -> Site-To-Site VPN -> Advanced -> Crypto Maps -> Edit tab,
  "Enable Perfect Forwarding Secrecy", with DH-Group 21 or 14 being selectable,
  attempts to select DH-Group 21 or 14 on that tab are ignored -- when I go to the
  Configuration -> Site-To-Site-VPN -> Connection Profiles -> Edit Connection Profile -> Advanced -> Crypto Maps
  tab, then the only choices are Diffie-Hellman Groups : { 2, 5, 15, 16 }, with Group5 selected by default,
  and if I change anything in the Connection Profile and save it, any PFS DH-Group setting gets
  reset to 5.

  So far, I've of course not been able to get the router to negotiate IKEv1 Phase 1 successfully with the gateway,
  probably because of this reason - our PFS DH-Group-{14,21} settings made in the Connection Profile,
  and in the IPSEC Profile in use, where we also select PFS Group-14 ,  are not being honored, and
  only the Group5 setting in the Crypto Maps entry , which only allows Groups { 2, 5, 15, 16 } to be used,
  takes effect.

  Please, can anyone suggest a way of getting our FPR-2110 to use either DH-Group-21 or DH-Group-14 with IKEv1 only,

  using ASDM 7.14(1) ?  Or is this just not possible ? 

 

Thanks & Best Regards,
Jason Vas Dias, SW & Sys Eng., Ireland

17 Replies 17

JVD66
Level 1
Level 1

Yes, we are using a totally different config now for IKEv2 - we are using DH-group21 for PFS .
We could not get IKEv1 working with or without PFS enabled, on ANY DH-group.

Yes using PFS DH 21 is same in both peers ?

JVD66
Level 1
Level 1

Yes, of course.
The IKEv2-only profile worked WITHOUT PFS, even though remote Peer had specified PFS group21, and it works
with PFS on group21.
The IKEv1-only profile could not be made to work at all, with or without PFS, despite over an hour's trying by a CISCO expert.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: