IPSec Diffie Hellman group DH20 issues?

triJRO
triJRO Posts: 10  Freshman Member
First Comment Friend Collector Fourth Anniversary
edited June 2023 in Security

Hi,

I'm currently trying to establish a IPSec VPN tunnel with my USG Flex 500 (
V5.36(ABUJ.2)) to a Palo Alto firewall to a customer. The settings do match between us but the connection can't be established. The debugging from customer side indicates that the Palo Alto uses ID 20 but from my side it reports ID 12 which doesn't exist although ID 20 is configured. Are there any known issues with using newer DH groups like 20 or 21?

All Replies

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @triJRO ,

    DH group 20 works in my lab test, can you send me IKE communication packets in PM.

    We would like to check ISAKMP SA payload

Security Highlight