Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Danny_Olson
Contributor

Recomended DH Group

Jump to solution

Hello, 

 

I just wanted to see if Check Point had an official recommendation for the DH Group? I was looking at sk27054, but I was not too clear when it comes to the AES-256 Encryption Algorithm. 

I have been reading if your using If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21 or 24, but check point does not recommend 24, and does does not look like it supports 21? 

is DH 19, or 20 recommended to protect an AES-256 KEY. or is it even compatible. 

or do you have to use IKEv2 in this case? 

I would like to use AES-256 and SHA-512 no PFS for P1 and P2, but i can you should you protect an AES-256KEY with a DH group that is designed for a 128bit key? 

I think i have to use 21, 24, but i don't want to compromise the stability that i currently have, which is excellent. 

Thanks in Advance, 

 

 

 

0 Kudos
1 Solution

Accepted Solutions
Danny_Olson
Contributor

Thanks so much. Yeah, I am not sure you can have both in this case. I am curious as to what people in my local area are doing, and also I will reach out to TAC to see if they bless this.

View solution in original post

4 Replies
the_rock
Champion
Champion

I dont know about official CP recommendation, but below link explains it well.

Andy

https://infosecmonkey.com/what-diffie-hellman-dh-group-should-i-use/

0 Kudos
Danny_Olson
Contributor

Thanks. I saw that in multiple places. Use 21 or higher to protect a 256key. I guess by the fact we are using an AES-256 Key puts you ahead of the game, but it's what DH group is supported or suited best to work protecting that key.

the_rock
Champion
Champion

Put it this way, like anything really in IT world, it boils down to this question...would you rather have performance or security? Sometimes, its not so easy to achieve both, specially now days.

0 Kudos
Danny_Olson
Contributor

Thanks so much. Yeah, I am not sure you can have both in this case. I am curious as to what people in my local area are doing, and also I will reach out to TAC to see if they bless this.