Quantcast
Channel: EdgeRouter topics
Viewing all articles
Browse latest Browse all 20028

IPSEC Phase2 PFS group1 not available

$
0
0

Just spend some time troubleshooting site to site VPN to Cisco IOS router.

I figured option "enable" would give me dh-group1 , but phase2 didn't came up 

admin@ERL# set vpn ipsec esp-group TS01 pfs ?
dh-group14  dh-group16  dh-group18  dh-group2   dh-group21  dh-group23  dh-group25  dh-group5   enable
dh-group15  dh-group17  dh-group19  dh-group20  dh-group22  dh-group24  dh-group26  disable

Swapping "enable" for dh-group2 both give me dh-group2.  Is this intentional?

V1.8.5

 


Viewing all articles
Browse latest Browse all 20028

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>