cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1083
Views
5
Helpful
3
Replies

What router models and IOS version is needed for Diffie-Hellman (DH) Group 14 and RSA SHA-256 of 2048bits?

Hi All, I need to build IPSec Tunnels where I can use:

 

1)Session key exchange algorithm & group: Change to DH group 14.

2)Algorithm used for integrity: Change to RSA SHA-256 2048 bit.


Which routers and version of ios support these features?

3 Replies 3

Hi @richard.retamozo 

They aren't the latest and most secure algorithms, but most Cisco hardware IOS router (ISR G2 or 1K/4K) or ASA/FTD will support those algorithms. If you run the latest software version you shouldn't have an issue.

Leo Laohoo
Hall of Fame
Hall of Fame

All crypto-enabled firmware can support, at a minimum, 2048.  

On FTD, I think 256 bits are only supported with IKEv2.