01-05-2021 06:44 AM - edited 01-05-2021 06:45 AM
I want to do site to site vpn with firepower and sophos XG firewall
when i config firepower have a PRF to setup but Sophos don't have PRF to setup
i wonder is it cause me setup not working
01-05-2021 06:56 AM
PRF is used in IKEv2. Are you selecting IKEv2 on Sophos or does Sophos not support IKEv2? If it does not support IKEv2 then you'd have to use IKEv1 which Firepower also supports.
01-05-2021 07:17 AM
I use iKEv2 to setup Sophos but I can not see the PRF option
01-05-2021 07:36 AM - edited 01-06-2021 05:14 AM
This is probably a question for Sophos rather than the Cisco forum. It may well be that PRF on the sophos is the same as integrity value, in your instance SHA-256. You could use IKEv1 if you don't get anywhere with Sophos, as IKEv1 doesn't use PRF.
FYI, don't use DH group 2 - it's weak and depreciated in the latest versions of software.
01-05-2021 03:15 PM
PRF if not support by each side or you not pretty sure it support then it better to disable it.
because if make traffic one direction and unknown behavior
01-05-2021 05:18 PM
I’ll ask sophos to this question
How to disable PRF on Cisco ?
it won’t let me blank...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide