Configuring Perfect Forward Secrecy

The following commands configure a crypto map entry for PFS:

RTA(config)#crypto map MAP-TO NY 20 ipsec-isakmp RTA(config-crypto-map)#set pfs groupl

The command set pfs groupl tells the router to use PFS on all IPsec SAs creatcd with this entry. By default, PFS is off. The keyword groupl specifies Diffie-Hellman group 1 (768-bit numbers). The other option, group2, specifies Diffie-Hellman group 2 (1024-bit numbers). Group 2 provides greater security but requires more time to compute. See "Internet Key Exchange" earlier in this chapter for more on PFS.

NOTE PFS provides better security than the alternative, which is the exchange of encrypted nonces. A nonce is a randomly generated number meant for one-time use. For instance, Alice and Bob can establish a new shared key by exchanging nonces that are encrypted with a shared key they already know. This is considered less secure than PFS because the new key is derived from the old key—discovering the old key helps an attacker find the new key too. With P1;S, on the other hand, the new key is created on its own with the Diffie-Hellman algorithm. The downside of PFS is the computational overhead required to generate a new Diffie-Hellman key each time.

Continue reading here: Enable Debugging and Clearing Existing SAs

Was this article helpful?

0 0

Readers' Questions

  • stephanie sanchez
    What is perfect forward secrecy?
    8 months ago
  • Perfect Forward Secrecy (PFS) is a system of cryptography that prevents any future compromise of encrypted data, even if the encryption key used at the time of transmission is compromised. It helps protect against potential hacks of data stored on vulnerable servers and against mass surveillance by governments and other third-party actors. PFS works by generating unique encryption keys for each session, meaning that any future attacks will not be able to decipher data encrypted during prior sessions.