SG
Size: a a a
SG
РН
SG
SG
РН
SG
SG
SG
ВН
ВН
ВН
РН
ВН
ВН
КБ
ms-dh-downgrade
Whether to allow a downgrade of DiffieHellman group during rekey (using CREATE_CHILD_SA). Microsoft Windows (at the time of writing, Feb 2018) defaults to using the very weak modp1024 (DH2). This can be changed using a Windows registry setting to use modp2048 (DH14). However, at rekey times, it will shamelessly use modp1024 again and the connection might fail. Setting this option to yes (and adding modp1024 proposals to the ike line) this will allow this downgrade attack to happen. This should only be used to support Windows that feature this bug. Currently the accepted values are no, (the default) or yes.
РН
ВН
ВН
ВН
SG