Skip to main content
CodeTron
Explorer II
January 20, 2025
Question

Site to Site VPN best practices

  • January 20, 2025
  • 0 replies
  • 537 views

Hi,

I'm trying to configure a S to S tunnel that achieves high security and the highest encryption possible. is the below setting sufficient enough?

 

Hardware

Two FG 80F running OS 7.4.3

 

Current tunnel configuration

No NAT

Authentication: Preshared key, IKEv2

Phase 1 Proposal AES256 SHA512 DH 21

Phase 2 Selectors AES256 SHA512 DH 21

 

A schedule is set to stop the policies when not in use (please let me know if this helps in enhancing the security)

Thanks in advanced

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!