Virtual Dave
For When You Can't Have The Real Thing
[
start
|
index
|
login
]
start
>
FortiOS
> 5.6 > DH Selection For IPsec VPNs
DH Selection For IPsec VPNs
Created by
dave
. Last edited by
dave
, 3 years and 327 days ago. Viewed 1,005 times. #1
[edit]
[
rdf
]
labels
attachments
(2019-03-13)
Problem
What DH value should I use for my IPsec tunnels?
As of March 2019
IKE:
IKEv1 is still acceptable, there's no burning reason to choose IKEv2 over v1
DH Group:
ideal is DH-19 or DH-20
minimum for reasonable security is DH-14, going below that is not recommended
Algorithms:
use AES-128 (or higher) with SHA-128 (or higher)
Always avoid DES
Avoid 3DES and/or MD5 if at all possible
References
some reddit thread somewhere which I can't find any more, yeah possibly sketchy AF maybe, but it's backed up by other places on the web
DH group, October 2018:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk27054
NCSC (UK) requirements for their tunnels, March 2019
https://www.ncsc.gov.uk/guidance/using-ipsec-protect-data
no comments |
post comment
see also:
snipsnap-index
FortiOS
snipsnap-notfound
snipsnap-search
snipsnap-help
VPN Debug
FortiOS LLDP
SSL Securi...
fortios
QOS Setup
Virtual Dave
Megaplex:
Home Page
This wiki's
start
page
Send Feedback To Dave
(read this
note about local search
)
Logged in Users: (0)
… and 5 Guests.
Recently Changed
Add New Disks To Grow Volume
VLAN IP Interface
Logging Volume Per-Adom
SSH No Key Exchange method found
Example nmcli Commands
etckeeper
What Program Has This Port Open
2022
Batmobile
Srv_features
2018
2014
Ferrari 333 SP
HotWheels
Custom '77 Dodge Van
Super Van
Fandango
Corvette C6R
Bone Shaker
Fire Eater
2021
2020
2019
2016
2013
2012
2011
2010
2008
2007
Editing:
snipsnap-help
,
Image Macro
(
Et auditum est, et idcirco ego nunc simulare
)
This is a collection of techical information, much of it learned the hard way. Consider it a lab book or a /info directory. I doubt much of it will be of use to anyone else.
Useful:
snipsnap-help
snipsnap-macro-help
Google
snipsnap.org
| Copyright 2000-2002 Matthias L. Jugel and Stephan J. Schmidt