Hi,
I just noticed after upgrading XG to 17.5.3 MR-3 and Sophos Connect client to version 1.2 that Diffie Hellman group changed from ECP_256 to MODP_1024. Also the VPN profile is referencing MODP_1024.
MODP_1024 is weak and depreciated so I suppose this is a configuration flaw? Are there any configuration options for Sophos Connect to change DH group and maybe move from CBC to a modern GCM cipher?
This thread was automatically locked due to age.