Avatar of penguins_rule
penguins_rule
Flag for United States of America asked on

Sonicwall TZ210 DH group reverts from 2 to 1

My sonicwall TZ210 periodically changes the DH group from 2 to 1 on one of the VPN connections. Is there a reason why?
VPNHardware FirewallsNetwork Security

Avatar of undefined
Last Comment
Blue Street Tech

8/22/2022 - Mon
Ugo Mena

What is the client using to connect to the SonicWall VPN?

Do you have "Enable Perfect Forward Secrecy" enabled?
Blue Street Tech

Hi penguins_rule,

Upgrade the firmware and retest.
penguins_rule

ASKER
Client has a Cisco ASA 5505
Enable Perfect Forward Secrecy is not enabled
Current firmware version is SonicOS Enhanced 5.5.1.0-5o

It's not convenient to upgrade the firmware unless it is really necessary.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Ugo Mena

Are you using Certificates or a preshared secret for IKE Policy?

Do you know what version ASA release client is running?

In general, I think you have an IKEv2 policy that is falling back to IKEv1 due to an IKEv2 incompatible device...
penguins_rule

ASKER
The connection works fine for several weeks at a time.
Then the DH Group reverts back to 1 on the Sonicwall. The client using the Cisco ASA 5500 cannot connect until the Sonicwall is changed back to DH group 2

Using IKE preshared key
ASA release client is not readily attainable
ASKER CERTIFIED SOLUTION
Ugo Mena

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
Blue Street Tech

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
penguins_rule

ASKER
thanks for your help. I will schedule an upgrade to the firmware. it may take a few weeks, i will post how it goes.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Blue Street Tech

No problem...we'll be here for you!
penguins_rule

ASKER
upgraded the firmware to the current version. On the reboot with current firmware, the DH group was changed from 2 to 1. I will have to wait and see if it changes again.
Blue Street Tech

That is nothing to worry about on the onset. Sometimes for compatibility reasons settings slightly change especially when going from deprecated firmware versions to new core releases.

I'd change it all to DH2 and then restart the SonicWALL. Everything should be OK thereafter.

Let me know how it goes!
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck