IPSEC VPN encryptions, authentication and Diffie-Hellman groups - a poll

QuiteSmart
QuiteSmart Posts: 46  Freshman Member
Fifth Anniversary Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security

Hello community,

this post if for anyone who uses to configure IPSEC VPNs (both L2TP both pure):

which encryption/authentication and DH groups do you use on each phase?

Have you ever performed speed test with different values?

Which is the minimum encryption that you consider safe?

Which is the minimum authentication that you consider safe?

Which is the minimum DH group?

All Replies

  • CHS
    CHS Posts: 181  Master Member
    Sixth Anniversary 5 Answers 10 Comments Friend Collector

    There's a perfect wizard that automatically generates the L2TP VPN configuration. I used it without making any additional changes, and I believe it should offer the best compatibility across different OS platforms.

    Phase 1: 3DES/SHA1/DH2
    Phase 2: 3DES/SHA1/None

Security Highlight