[strongSwan] seeking advice: pfs on creating a child_sa?

John Brown jb20141125 at gmail.com
Tue Mar 1 12:55:56 CET 2016


Hi,

 I can give you two links with some small amount information about your
question:

http://www.juniper.net/documentation/en_US/junos12.1x46/topics/concept/vpn-security-phase-2-ipsec-proposal-understanding.html

and

https://wiki.strongswan.org/projects/strongswan/wiki/SecurityRecommendations#Perfect-Forward-Secrecy-PFS


Regards,

John

2016-03-01 11:23 GMT+01:00 Harald Dunkel <harald.dunkel at aixigo.de>:

> Hi folks,
>
> looking for some advice: Would you suggest to use pfs for esp?
> Apparently pfs is a must-have to establish an ike_sa today, but
> is this reasonable for the child_sas as well?
>
> Every helpful comment is highly appreciated
> Harri
> _______________________________________________
> Users mailing list
> Users at lists.strongswan.org
> https://lists.strongswan.org/mailman/listinfo/users
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20160301/bb9bf662/attachment.html>


More information about the Users mailing list