New Member
October 29, 2015
Question
Fortigate to Fortigate IPsec site to site VPN - Wont form with DH 19-21 Elliptic curve
- October 29, 2015
- 2 replies
- 6215 views
Hello every one. I believe i found a bug. so setting up a site to site IPSEC VPN between 100D 5.2.1 and 60D 5.2.0.
When I tried using the below DH groups for the phase1 the devices kept giving me some weird errors..
DH Group 19: 256-bit random ECP Group DH Group 20: 384-bit random ECP Group DH Group 21: 521-bit random ECP Group
When I take the DH group down to DH18 its works right away.
Has anyone else ran across this? From what i've been reading ECC is going to be the wave of the future.
Regards,
Daniel
