This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect using depreciated DH group?

Hi,

I just noticed after upgrading XG to 17.5.3 MR-3 and Sophos Connect client to version 1.2 that Diffie Hellman group changed from ECP_256 to MODP_1024. Also the VPN profile is referencing MODP_1024.

MODP_1024 is weak and depreciated so I suppose this is a configuration flaw? Are there any configuration options for Sophos Connect to change DH group and maybe move from CBC to a modern GCM cipher?

 



This thread was automatically locked due to age.
Parents Reply Children
  • Hello Anders,

    In the .tgb file you need to make this change in this line. Transforms = AES256-SHA2_256-GRP19-RSA_SIG

     

    Similarly for Phase 2 you need to change this line. Transforms = TGBQM-ESP-AES256-SHA2_256-PFSGRP19-TUN-XF

     

    This change will help to select the correct DH group. This is a problem with Sophos Connect 1.2 and it will be fixed in the next release and by default it will select ECP_256.

     

    Please let me know if you have any questions.

     

    Ramesh