This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[5.012] Authentication Algorithm MD 128bit gone

Hi Group,

I just update from 5.011 --> 5.012

After the update my IPSec Policies are changed from MD 128bit to MD 160Bit and now we don't have the option of 128bit

What should we do know?

TIA
Marc


This thread was automatically locked due to age.
Parents Reply Children
  • But where is my fault?

    This is my VPN-Status:

    000 "S_XXXXXXXXXXXXX_0":   CAs: '%any'...'%any'
    000 "S_XXXXXXXXXXXXX_0":   ike_life: 14400s; ipsec_life: 3600s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
    000 "S_XXXXXXXXXXXXX_0":   policy: PSK+ENCRYPT+TUNNEL; interface: eth1; unrouted
    000 "S_XXXXXXXXXXXXX_0":   newest ISAKMP SA: #1; newest IPsec SA: #0; eroute owner: #0
    000 "S_XXXXXXXXXXXXX_0":   IKE algorithms wanted: 5_000-1-2, flags=-strict
    000 "S_XXXXXXXXXXXXX_0":   IKE algorithms found:  5_192-1_128-2, 
    000 "S_XXXXXXXXXXXXX_0":   IKE algorithm newest: 3DES_CBC_192-MD5-MODP1024
    000 "S_XXXXXXXXXXXXX_0":   ESP algorithms wanted: 3_000-1, flags=-strict
    000 "S_XXXXXXXXXXXXX_0":   ESP algorithms loaded: 3_168-1_128, 
    000  
    000 #76: "S_XXXXXXXXXXXXX_0" STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in 9s
    000 #1: "S_XXXXXXXXXXXXX_0" STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in 8364s; newest ISAKMP
    000  


    Where is the differenz between 5.011 and 5.012

    TIA 
    Marc
  • I found the changes!!!

    After the update the PFS-Settings was changed from PFS Group 2 to no PFS

    After changing back all is working

    Regard Marc