DH Group # | Group Description | RFC | Recommendation |
---|---|---|---|
1 | 768 bit modulus | RFC 2049 | AVOID Available for use in IKEv1 * IKEv2 |
2 | 1024 bit modulus | RFC 2049 | AVOID Available for use in IKEv1 * IKEv2 |
3 | EC2N group over GF[2^155] | RFC 2049 | Not available for use in modern IKE implementations. |
4 | EC2N group over GF[2^185] | RFC 2049 | Not available for use in modern IKE implementations. |
5 | 1536 bit modulus | RFC 3526 | AVOID Available for use in IKEv1 * IKEv2 |
6 | EC2N group over GF[2^163] | IETF Draft | Not available for use in modern IKE implementations. |
7 | EC2N group over GF[2^163] | IETF Draft | AVOID Available for use in IKEv1 |
8 | EC2N group over GF[2^283] | IETF Draft | Not available for use in modern IKE implementations. |
9 | EC2N group over GF[2^283] | IETF Draft | Not available for use in modern IKE implementations. |
10 | EC2N group over GF[2^409] | IETF Draft | Not available for use in modern IKE implementations. |
11 | EC2N group over GF[2^409] | IETF Draft | Not available for use in modern IKE implementations. |
12 | EC2N group over GF[2^571] | IETF Draft | Not available for use in modern IKE implementations. |
13 | EC2N group over GF[2^571] | IETF Draft | Not available for use in modern IKE implementations. |
14 | 2048-bit modulus | RFC 3526 | MINIMUM ACCEPTABLE Available for use in IKEv2 |
15 | 3072-bit modulus | RFC 3526 | Not available for use in modern IKE implementations. |
16 | 4096-bit modulus | RFC 3526 | Not available for use in modern IKE implementations. |
17 | 6144-bit modulus | RFC 3526 | Not available for use in modern IKE implementations. |
18 | 8192-bit modulus | RFC 3526 | Not available for use in modern IKE implementations. |
19 | 256-bit random elliptic curve | RFC 5903 | Available for use in IKEv2 |
20 | 384-bit random elliptic curve | RFC 5903 | Available for use in IKEv2 |
21 | 521-bit random elliptic curve | RFC 5903 | Available for use in IKEv2 |
22 | 1024-bit modulus with 160-bit prime order subgroup | RFC 5114 | Not available for use in modern IKE implementations. |
23 | 2048-bit modulus with 224-bit prime order subgroup | RFC 5114 | Not available for use in modern IKE implementations. |
24 | 2048-bit modulus with 256-bit prime order subgroup | RFC 5114 | Available for use in IKEv2 |
25 | 192-bit Random ECP Group | RFC 5114 | Not available for use in modern IKE implementations. |
26 | 224-bit Random ECP Group | RFC 5114 | Not available for use in modern IKE implementations. |
27 | 224-bit Random ECP Group | RFC 6932 | Not available for use in modern IKE implementations. |
28 | 256-bit Brainpool ECP group | RFC 6932 | Not available for use in modern IKE implementations. |
29 | 384-bit Brainpool ECP group | RFC 6932 | Not available for use in modern IKE implementations. |
30 | 512-bit Brainpool ECP group | RFC 6932 | Not available for use in modern IKE implementations. |
31-32767 | Unassigned | ||