Community discussions

MikroTik App
 
truster
just joined
Topic Author
Posts: 1
Joined: Tue Feb 23, 2016 12:10 am

Feature not accessible through winbox

Tue Feb 23, 2016 12:17 am

Hello,

the feature "multiple DH groups for phase 1" introduced with version 6.34 is still missing in the Winbox configuration. i can select only one through the GUI. But you can set multiple DH Groups through the console.

i spend an hour to figure it out :-)

best regards,
dave
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: Feature not accessible through winbox

Wed May 11, 2016 11:40 am

Probably an experimental option. Not sure if it is a good experiment, other implementations I know do not support this
so I presume there is a protocol standards issue.
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2103
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: Feature not accessible through winbox

Wed May 11, 2016 12:41 pm

Probably an experimental option. Not sure if it is a good experiment, other implementations I know do not support this
so I presume there is a protocol standards issue.
I know for a fact that Fortinet support multiple DH groups.

It does not use all of them at once (obviously), it just means it will match on any of the specified DH groups.

So if you specify DH2 and DH5, the remote peer can use either or.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: Feature not accessible through winbox

Wed May 11, 2016 3:01 pm

Yes, but in the documentation of e.g. racoon on Linux, where you could configure this, it warns that this is not
going to work. I guess there is something in the protocol or in existing implementations that might cause problems.
Maybe a trick was found to work around this. (like alternating these settings on subsequent sessions until one works)
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7053
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Feature not accessible through winbox

Wed May 11, 2016 3:54 pm

Winbox support for this new feature is already added (v6.35.2 definitely have it).
It works as nz_monkey stated, picked one from the set of supported DH groups. Also note that whenever possible strongest will be used first.
Feature was added to support as many devices as possible in road warrior setups, because recent windows phones works only with 2048, but iphones only with 1024.

Who is online

Users browsing this forum: Bing [Bot] and 131 guests