Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

IOS to ASA with DH group 14

Has any one had the pleasure of trying to build a VPN tunnel between IOS and ASA using ikev1 and DH group 14?

The ASDM allows me to select grooup 14 but the CLI returns an error when the command is applied.

1 ACCEPTED SOLUTION

Accepted Solutions
VIP Purple

IOS to ASA with DH group 14

You need to move to IKEv2, there you have support for DH-Group 14 both on IOS and the ASA.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

5 REPLIES

IOS to ASA with DH group 14

hi,

was the error on the router IOS? could you post the CLI error?

Community Member

IOS to ASA with DH group 14

No it was in the asa. The asa woul only take 'group 1.2,5 or 7'

VIP Purple

IOS to ASA with DH group 14

You need to move to IKEv2, there you have support for DH-Group 14 both on IOS and the ASA.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Community Member

IOS to ASA with DH group 14

Thats a shame becuase my IOS devices is in production, not sure I'll be able to move to IKEv2

VIP Purple

IOS to ASA with DH group 14

Thats a shame becuase my IOS devices is in production, not sure I'll be able to move to IKEv2

Yes, it would be really nice to have that on the ASA. Are you already on DH5 for your VPNs? With that you had at least more security then the avarage VPN-Admin. Most VPNs I see are still running DH2 (and some to my astonishment even with DH1).

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

2007
Views
0
Helpful
5
Replies
CreatePlease to create content