Help Center> Virtual Private Network> FAQs> Classic VPN> Related Operations on the Console> How Do I Disable PFS When Creating a VPN Connection?
Updated on 2023-06-16 GMT+08:00

How Do I Disable PFS When Creating a VPN Connection?

You can disable Perfect Forward Secrecy (PFS) in some Huawei Cloud regions. You are advised to enable PFS in your on-premises data center, because it improves IKE negotiation security in phase 2.

By default, PFS is disabled on some vendors' devices. Check the device configuration manual to ensure that PFS is enabled.

  • PFS is a security feature.

    IKE negotiation has two phases, phase one and phase two. The key of phase two (IPsec SA) is derived from the key generated in phase one. Once the key in phase one is disclosed, the security of the IPsec VPN may be adversely affected. To improve the key security, IKE provides PFS. After PFS is configured, an additional DH exchange will be performed during IPsec SA negotiation, and a new IPsec SA key will be generated, improving IPsec SA security.

  • To ensure security, PFS is enabled on Huawei Cloud by default. Ensure that PFS is also enabled on the on-premises gateway. Otherwise, the negotiation will fail.

Related Operations on the Console FAQs

more