05-13-2022 12:37 PM
Good day -
I am trying to configure an FPR-2110, to follow instructions on connecting to an APN gateway,
which specifies to use a VTI IPSEC with IKEv1 pre-shared key only with PFS enabled ,
DH-Group-21 initially, which they kindly changed to DH-Group-14 for us, but now I find,
though I can select on the Configuration -> Site-To-Site VPN -> Advanced -> Crypto Maps -> Edit tab,
"Enable Perfect Forwarding Secrecy", with DH-Group 21 or 14 being selectable,
attempts to select DH-Group 21 or 14 on that tab are ignored -- when I go to the
Configuration -> Site-To-Site-VPN -> Connection Profiles -> Edit Connection Profile -> Advanced -> Crypto Maps
tab, then the only choices are Diffie-Hellman Groups : { 2, 5, 15, 16 }, with Group5 selected by default,
and if I change anything in the Connection Profile and save it, any PFS DH-Group setting gets
reset to 5.
So far, I've of course not been able to get the router to negotiate IKEv1 Phase 1 successfully with the gateway,
probably because of this reason - our PFS DH-Group-{14,21} settings made in the Connection Profile,
and in the IPSEC Profile in use, where we also select PFS Group-14 , are not being honored, and
only the Group5 setting in the Crypto Maps entry , which only allows Groups { 2, 5, 15, 16 } to be used,
takes effect.
Please, can anyone suggest a way of getting our FPR-2110 to use either DH-Group-21 or DH-Group-14 with IKEv1 only,
using ASDM 7.14(1) ? Or is this just not possible ?
Thanks & Best Regards,
Jason Vas Dias, SW & Sys Eng., Ireland
Solved! Go to Solution.
05-17-2022 11:24 AM
Yes, we are using a totally different config now for IKEv2 - we are using DH-group21 for PFS .
We could not get IKEv1 working with or without PFS enabled, on ANY DH-group.
05-17-2022 11:56 AM
Yes using PFS DH 21 is same in both peers ?
05-18-2022 02:51 AM
Yes, of course.
The IKEv2-only profile worked WITHOUT PFS, even though remote Peer had specified PFS group21, and it works
with PFS on group21.
The IKEv1-only profile could not be made to work at all, with or without PFS, despite over an hour's trying by a CISCO expert.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: