Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: VPN IPSEC - ECP or MODP encryption?

$
0
0

Hi dmisan


Greetings,

 

As per my understanding we can decide on the better algorithm depending on the key size. I believe ECP outperforms the MODP algorithm. dh-group - group21 options introduced in Junos OS Release 19.1R1 on SRX Series devices and is supported on many SRX devices, the link below lists the devices and versions which support DH group 21.

Link : IPsec VPN security services support new authentication algorithm and Diffie-Hellman (DH) group values 

 

but I recommend you to refer the below details: 

DES and 3DES does not need as strong a DH group, however DES and 3DES should never be used unless you are under some encryption restriction based on country restriction.  AES should use a stronger DH Group.  

  • If you are using encryption or authentication algorithms with a 128-bit key, use Diffie-Hellman groups 19, 20.
  • If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21.
  • The RFC 5114 Section 4 states DH Group 24 strength is about equal to a modular key that is 2048-bits long, that is not strong enough to protect 128 or 256-bit AES, you should stay away from 24.

 

Refer the below links for more details:  

1)    What Diffie-Hellman (DH) Group Should I Use 
2)    Diffie-Hellman Groups for Use with IETF Standards 

 

Hope this helps. Smiley Happy

 

Please mark "Accept as solution" if this answers your query. 

Kudos are appreciated too! 

 

Regards, 

Sharat Ainapur


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>