Fortinet black logo

Admin Guide (Standalone)

IPsec VPN supports more DH groups

IPsec VPN supports more DH groups

Diffie-Hellman (DH) key exchange in phase1 is used to negotiate and exchange private keys for phase2. FortiExtender now provides more DH group options. New DH group options ("15", "16", "17", "18", "19", "20", "21", "27", "28", "29", "30", "31", "32") are added to the ipsec phase1-interface/phase2-interface config file.

Any DH groups less than 15 are not recommended due to their low security levels. And Elliptic Curve Groups ("19", "20", "21", "27", "28", "29", "30", "31", "32") offer better security compared to the MODP groups ("1", "2", "5", "14", "15", "16", "17", "18"). The DH groups in phase2 should be set to the same value as those for phase1, and PFS is recommended.

IPsec VPN supports more DH groups

Diffie-Hellman (DH) key exchange in phase1 is used to negotiate and exchange private keys for phase2. FortiExtender now provides more DH group options. New DH group options ("15", "16", "17", "18", "19", "20", "21", "27", "28", "29", "30", "31", "32") are added to the ipsec phase1-interface/phase2-interface config file.

Any DH groups less than 15 are not recommended due to their low security levels. And Elliptic Curve Groups ("19", "20", "21", "27", "28", "29", "30", "31", "32") offer better security compared to the MODP groups ("1", "2", "5", "14", "15", "16", "17", "18"). The DH groups in phase2 should be set to the same value as those for phase1, and PFS is recommended.