Skip to Main Content
Status Not under consideration
Workspace * IBM Cloud Ideas
Created by Guest
Created on Nov 18, 2020

Improve VPN Security with a Fortigate Peer

Currently a VPC VPN Connection to a Fortigate Peer is required using very unsecure settings:

  • Enable DH-group 2 in the Phase 1 proposal.

  • Disable PFS in the Phase 2 proposal.

A higher DH-group is not working and not supported, at least what support is telling us.

So please provide better security settings for the Fortigate, which is a widely used VPN gateway. DH-group 2 is considered as unsecure!

Idea priority High
  • Guest
    Aug 23, 2022

    The request has been marked as "not under consideration" for the following reasons:

    • The customer may be following the documentation which was just providing an example configuration. IBM Cloud VPN offer more ciphers than just DH group 2.

    • Support for additional and more secure ciphers will be tracked with other epics. VPNVPC-111 and VPNVPC-99

  • Guest
    Jul 8, 2021

    It does not appear there is a firewall in place or ability to integrate with security groups within VPC to filter who can connect to the VPC VPN peer. This is needed so that route based and policy based VPC VPNs are not reached by any VPN clients and can be filtered.