Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Route based IPSEC VPN Config between SSG-550M and Cisco ASA

$
0
0

Hello Ishaik,

 

About PFS - please check Vikas's post again. PFS is not a checkbox in ScreenOS. It is a part of your proposal set. In your screenshot, I see both proposals use Group-2, which means PFS is enabled. If you click the drop down, you will see some proposals (shown already by Vikas) which have 'no-pfs'. As long as you are using proposals that do not contain the no-pfs keyword, PFS is enabled.

 

Since the other end is a non-ScrenOS box, I'd advice that you add individual proxy-IDs for every subnet you like to talk via the VPN. If there are too many subnets, see if you can configure a 0.0.0.0/0 proxy-id on both sides.


Viewing all articles
Browse latest Browse all 2577

Trending Articles