0
Votes

Add more DH Groups - Especially for Flagship Routers

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
 
0
Votes

Add more DH Groups - Especially for Flagship Routers

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Add more DH Groups - Especially for Flagship Routers
Add more DH Groups - Especially for Flagship Routers
2024-11-19 23:15:51
Model: ER7206 (TL-ER7206)  
Hardware Version: V3
Firmware Version:

Customer needs a VPN to a healthcare provider and I had to buy a Forigate because the tunnel needed DH20 pn the IPSEC Phase-2. (19 was a backup option)

 

The 7206 topped out at 14.

 

Any plans to add additional features for something like this?

 

I just fired up an older FortiGate (50E iirc) and it went to (PFS) DH32.

 

 

 

 

#1
Options
1 Reply
Re:Add more DH Groups - Especially for Flagship Routers
2024-11-21 02:04:39

Hi @EIBROG 

Thanks for posting in our business forum.

There is no plan as far as I know.

 

FYI, more DH groups mean more performance is required, which means the overall performance is needed.

It seems to be sensable to add more DH to new hardware.

#2
Options