Currently a VPC VPN Connection to a Fortigate Peer is required using very unsecure settings:
Enable DH-group 2 in the Phase 1 proposal.
Disable PFS in the Phase 2 proposal.
A higher DH-group is not working and not supported, at least what support is telling us.
So please provide better security settings for the Fortigate, which is a widely used VPN gateway. DH-group 2 is considered as unsecure!
| Idea priority | High |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
The request has been marked as "not under consideration" for the following reasons:
The customer may be following the documentation which was just providing an example configuration. IBM Cloud VPN offer more ciphers than just DH group 2.
Support for additional and more secure ciphers will be tracked with other epics. VPNVPC-111 and VPNVPC-99
It does not appear there is a firewall in place or ability to integrate with security groups within VPC to filter who can connect to the VPC VPN peer. This is needed so that route based and policy based VPC VPNs are not reached by any VPN clients and can be filtered.