cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3080
Views
0
Helpful
5
Replies

IOS to ASA with DH group 14

martinbuffleo
Level 1
Level 1

Has any one had the pleasure of trying to build a VPN tunnel between IOS and ASA using ikev1 and DH group 14?

The ASDM allows me to select grooup 14 but the CLI returns an error when the command is applied.

1 Accepted Solution

Accepted Solutions

You need to move to IKEv2, there you have support for DH-Group 14 both on IOS and the ASA.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

View solution in original post

5 Replies 5

johnlloyd_13
Level 9
Level 9

hi,

was the error on the router IOS? could you post the CLI error?

No it was in the asa. The asa woul only take 'group 1.2,5 or 7'

You need to move to IKEv2, there you have support for DH-Group 14 both on IOS and the ASA.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Thats a shame becuase my IOS devices is in production, not sure I'll be able to move to IKEv2

Thats a shame becuase my IOS devices is in production, not sure I'll be able to move to IKEv2

Yes, it would be really nice to have that on the ASA. Are you already on DH5 for your VPNs? With that you had at least more security then the avarage VPN-Admin. Most VPNs I see are still running DH2 (and some to my astonishment even with DH1).

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: