Virtual Dave
For When You Can't Have The Real Thing
[
start
|
index
|
login
]
start
>
FortiOS
> 5.6 > DH Selection For IPsec VPNs
DH Selection For IPsec VPNs
Created by
dave
. Last edited by
dave
, one year and 351 days ago. Viewed 635 times. #1
[edit]
[
rdf
]
labels
attachments
(2019-03-13)
Problem
What DH value should I use for my IPsec tunnels?
As of March 2019
IKE:
IKEv1 is still acceptable, there's no burning reason to choose IKEv2 over v1
DH Group:
ideal is DH-19 or DH-20
minimum for reasonable security is DH-14, going below that is not recommended
Algorithms:
use AES-128 (or higher) with SHA-128 (or higher)
Always avoid DES
Avoid 3DES and/or MD5 if at all possible
References
some reddit thread somewhere which I can't find any more, yeah possibly sketchy AF maybe, but it's backed up by other places on the web
DH group, October 2018:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk27054
NCSC (UK) requirements for their tunnels, March 2019
https://www.ncsc.gov.uk/guidance/using-ipsec-protect-data
no comments |
post comment
see also:
snipsnap-notfound
FortiOS
VPN Debug
snipsnap-search
FortiOS LLDP
SSL Securi...
QOS Setup
Virtual Dave
Megaplex:
Home Page
This wiki's
start
page
Send Feedback To Dave
(read this
note about local search
)
Logged in Users: (2)
dave
Googlebot
… and 3 Guests.
Recently Changed
Useful tshark Examples
DHCP Reservations
PHP 7
Find Transparent Proxy Systems
Active Directory with SSSD
Could Not Format Alternate Root
Use User's Password As Enable Password
VPN Status
Startup Control
nbtstat for Linux
Additional Disk
SSH pubkey authentication
CLI Restore Configuration
Example nmcli Commands
tls
macwatch
mac address
BGP Sessions
BGP Neighbors
Unifi Controller
Show Known Wifi Passwords
docker
Remove Host ID
snmpd crash in "Check_HR_FileSys_AutoFs
execute command on hosts
facts
Grow A LVM Partition
FortiClient Error Codes
Test Authentication Server
2020
Editing:
snipsnap-help
,
Image Macro
(
Et auditum est, et idcirco ego nunc simulare
)
This is a collection of techical information, much of it learned the hard way. Consider it a lab book or a /info directory. I doubt much of it will be of use to anyone else.
Useful:
snipsnap-help
snipsnap-macro-help
Google
snipsnap.org
| Copyright 2000-2002 Matthias L. Jugel and Stephan J. Schmidt