Configuring Perfect Forward Secrecy
The following commands configure a crypto map entry for PFS:
RTA(config)#crypto map MAP-TO NY 20 ipsec-isakmp RTA(config-crypto-map)#set pfs groupl
The command set pfs groupl tells the router to use PFS on all IPsec SAs creatcd with this entry. By default, PFS is off. The keyword groupl specifies Diffie-Hellman group 1 (768-bit numbers). The other option, group2, specifies Diffie-Hellman group 2 (1024-bit numbers). Group 2 provides greater security but requires more time to compute. See "Internet Key Exchange" earlier in this chapter for more on PFS.
NOTE PFS provides better security than the alternative, which is the exchange of encrypted nonces. A nonce is a randomly generated number meant for one-time use. For instance, Alice and Bob can establish a new shared key by exchanging nonces that are encrypted with a shared key they already know. This is considered less secure than PFS because the new key is derived from the old key—discovering the old key helps an attacker find the new key too. With P1;S, on the other hand, the new key is created on its own with the Diffie-Hellman algorithm. The downside of PFS is the computational overhead required to generate a new Diffie-Hellman key each time.
Continue reading here: Enable Debugging and Clearing Existing SAs
Was this article helpful?
Readers' Questions
-
stephanie sanchez8 months ago
- Reply