A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?
The IPsec Crypto profile is used for IKE phase 2 and includes the DH Group setting for PFS. By setting the DH Group to group14 in the IPsec Crypto profile, the firewall will propose PFS with group14 during phase 2, ensuring that the IPsec SA uses PFS with the specified group.
Why this answer
Perfect Forward Secrecy for IKE phase 2 is configured in the IPsec Crypto profile. The DH Group field in this profile specifies the Diffie-Hellman group used for PFS during phase 2. Setting it to group14 ensures that the IPsec SA uses PFS with group14.
The IKE Crypto profile controls phase 1, while the IPsec Crypto profile controls phase 2.
Exam trap
The trap here is confusing the IKE Crypto profile with the IPsec Crypto profile, or thinking that PFS is configured at the gateway or tunnel level.