- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello,
I just wanted to see if Check Point had an official recommendation for the DH Group? I was looking at sk27054, but I was not too clear when it comes to the AES-256 Encryption Algorithm.
I have been reading if your using If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21 or 24, but check point does not recommend 24, and does does not look like it supports 21?
is DH 19, or 20 recommended to protect an AES-256 KEY. or is it even compatible.
or do you have to use IKEv2 in this case?
I would like to use AES-256 and SHA-512 no PFS for P1 and P2, but i can you should you protect an AES-256KEY with a DH group that is designed for a 128bit key?
I think i have to use 21, 24, but i don't want to compromise the stability that i currently have, which is excellent.
Thanks in Advance,
Thanks so much. Yeah, I am not sure you can have both in this case. I am curious as to what people in my local area are doing, and also I will reach out to TAC to see if they bless this.
I dont know about official CP recommendation, but below link explains it well.
Andy
https://infosecmonkey.com/what-diffie-hellman-dh-group-should-i-use/
Thanks. I saw that in multiple places. Use 21 or higher to protect a 256key. I guess by the fact we are using an AES-256 Key puts you ahead of the game, but it's what DH group is supported or suited best to work protecting that key.
Put it this way, like anything really in IT world, it boils down to this question...would you rather have performance or security? Sometimes, its not so easy to achieve both, specially now days.
Thanks so much. Yeah, I am not sure you can have both in this case. I am curious as to what people in my local area are doing, and also I will reach out to TAC to see if they bless this.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY