Help Center/ Virtual Private Network/ FAQs/ Operations on the Console/ How Do I Disable PFS When Creating a VPN Connection?
Updated on 2024-07-23 GMT+08:00

How Do I Disable PFS When Creating a VPN Connection?

  • Cloud side

    In the VPN connection configuration, set PFS in the IPsec policy to Disable. By default, PFS is enabled on the cloud side.

  • Customer gateway in your on-premises data center

    By default, PFS is disabled on some vendors' devices. For details about how to disable PFS, see the corresponding product documentation.

Ensure that the PFS settings on the cloud side and the customer gateway are consistent. Otherwise, the negotiation will fail.

For security purposes, you are advised to enable PFS on both the cloud side and the customer gateway.