Why are some DH options missing from SecuExtender?

Zyxel_James
Zyxel_James Posts: 663  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

Question:
For old version of SecuExtender(IPSec_6.6.87.108), it supports the DH options from DES, 3DES, SHA-1, DH1, all the way to DH21.
However, why DES, 3DES, SHA-1, DH 1, DH 2, DH 5 are missing from the new version of SecuExtender VPN client (IPSec_SSL_VPN_7.7.40.019).

Answer:
We remove DES, 3DES, SHA-1, DH 1, DH 2, DH 5 from SecuExtender(IPSec_SSL_VPN_7.7.40.019) for security reasons, these algorithms are vulnerable.