0
Votes

Add more DH Groups - Especially for Flagship Routers

 
0
Votes

Add more DH Groups - Especially for Flagship Routers

Add more DH Groups - Especially for Flagship Routers
Add more DH Groups - Especially for Flagship Routers
Tuesday
Model: ER7206 (TL-ER7206)  
Hardware Version: V3
Firmware Version:

Customer needs a VPN to a healthcare provider and I had to buy a Forigate because the tunnel needed DH20 pn the IPSEC Phase-2. (19 was a backup option)

 

The 7206 topped out at 14.

 

Any plans to add additional features for something like this?

 

I just fired up an older FortiGate (50E iirc) and it went to (PFS) DH32.

 

 

 

 

#1
Options
1 Reply
Re:Add more DH Groups - Especially for Flagship Routers
Thursday

Hi @EIBROG 

Thanks for posting in our business forum.

There is no plan as far as I know.

 

FYI, more DH groups mean more performance is required, which means the overall performance is needed.

It seems to be sensable to add more DH to new hardware.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
#2
Options