Re: Cisco IPSEC proposals

2009-03-05 Thread Hans-Joerg Hoexer
On Thu, Mar 05, 2009 at 02:32:36PM -0700, Cameron Schaus wrote: > I recently configured an IPSEC tunnel between OpenBSD 4.4 machine and a Cisco > gateway. I had trouble during the key exchange because I had configured DH > group 2. The Cisco sent a proposal for DH group 5 with a lifetime of 780

Cisco IPSEC proposals

2009-03-05 Thread Cameron Schaus
I recently configured an IPSEC tunnel between OpenBSD 4.4 machine and a Cisco gateway. I had trouble during the key exchange because I had configured DH group 2. The Cisco sent a proposal for DH group 5 with a lifetime of 7800 seconds, along with a proposal for DH group 2 with a lifetime of 0