We help IT Professionals succeed at work.

I am using the ASDM VPN Wizard on my ASA 5505.  I'm not sure if I should check Enable Perfect Forwarding Secrecy (PFS)?

Medium Priority
Last Modified: 2012-05-06
I am creating a VPN between a Cisco ASA 5505 and a Cisco 2801 Router.  When I am going through the VPN Wizard on the ASA, it has a check box that is check by default that says "Enable Perfect Forwarding Secrecy (PFS)?  I didn't see anything like that on the 2801.  Do I leave that checked on the ASA.  When I do leave it checked I have this entry on my crypto map "crypto map outside_map 1 set pfs group 1".  There is nothing like that on the 2801 side.  The ASA is not in production yet, that why I havn't tested it to see if it works the way I have it configured now.  I'm trying to get is preconfiged and wasn't sure what the above meant, or if I needed it.  Thanks
Watch Question

Top Expert 2010

It depends on the endpoint of the VPN.   For example, the linksys RV042 does not use the PFS when doing a VPN to the ASA.  

Just make sure that both sides match exactly.  

Perfect Forward Secrecy (PFS) allows you to add an additional security parameter to tunnel sessions. PFS means that every time encryption and/or authentication key are computed, a new Diffie-Hellman Key Exchange is included.


The end point is a cisco 2801.  I don't see PFS being used on the 2801 side, so I won't use it on the ASA side.  Thanks
Top Expert 2010
PFS just adds a little extra security.    For it to work, both sides must match exactly.   So if its off on the 2800, remove it from the ASA.  

If you can enable it on the 2800, a little extra security never hurts.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts


Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.