Hello,
I just wanted to see if Check Point had an official recommendation for the DH Group? I was looking at sk27054, but I was not too clear when it comes to the AES-256 Encryption Algorithm.
I have been reading if your using If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21 or 24, but check point does not recommend 24, and does does not look like it supports 21?
is DH 19, or 20 recommended to protect an AES-256 KEY. or is it even compatible.
or do you have to use IKEv2 in this case?
I would like to use AES-256 and SHA-512 no PFS for P1 and P2, but i can you should you protect an AES-256KEY with a DH group that is designed for a 128bit key?
I think i have to use 21, 24, but i don't want to compromise the stability that i currently have, which is excellent.
Thanks in Advance,