Longer Diffie-Hellman key lengths.

by Cyrus Lok on Wednesday, March 3, 2010 at 1:03pm

cisco IOS 12.4 used to support only DH1, DH2 and DH5 under the isakmp configuration. The cisco IOS version 15 however supports more DH groups with longer key lengths:

R0(config-isakmp)#group ?
1 Diffie-Hellman group 1 (768 bit)
14 Diffie-Hellman group 14 (2048 bit)
15 Diffie-Hellman group 15 (3072 bit)
16 Diffie-Hellman group 16 (4096 bit)
2 Diffie-Hellman group 2 (1024 bit)
5 Diffie-Hellman group 5 (1536 bit)


