JunosE 11.3.x Command Reference Guide N to Z
tunnel pfs group
Syntax
Release Information
Description
Options
Mode
1370
tunnel pfs group { 1 | 2 | 5 }
no tunnel pfs group
Command introduced before JunosE Release 7.1.0.
Configures perfect forward secrecy for the IPSec tunnel by assigning a Diffie-Hellman
prime modulus group. The no version removes PFS from this tunnel.
1—Assigns a 768-bit Diffie-Hellman prime modulus group
2—Assigns a 1024-bit Diffie-Hellman prime modulus group
5—Assigns a 1536-bit Diffie-Hellman prime modulus group
Interface Configuration
Copyright © 2010, Juniper Networks, Inc.