dhgroup

Configures a Diffie-Hellman (DH) group for an Internet Key Exchange version 2 (IKEv2) proposal.
Syntax
dhgroup { 14 | 19 | 20 }
no dhgroup { 14 | 19 | 20 }
Command Default

The default DH group is 20.

Parameters
14
Specifies the 2048-bit modular exponential (MODP) DH group.
19
Specifies the 256-bit elliptical curve DH (ECDH) group.
20
Specifies the 384-bit ECDH group.
Modes

IKEv2 proposal configuration mode

Usage Guidelines

Diffie-Hellman negotiations are a part of the IKEv2 negotiations used to establish a secure communications channel.

Multiple DH groups may be configured for an IKEv2 proposal.

When only one DH group is configured for an IKEv2 proposal, removing it restores the default configuration.

The no form of the command removes the specified DH group configuration.

Examples

The following example configures the 2048-bit MODP DH group (14) for an IKEv2 proposal named ikev2_proposal.

device(config)# ikev2 proposal ikev2_proposal
device(config-ikev2-proposal-ikev2_proposal)# dhgroup 14
History
Release version Command history
08.0.50 This command was introduced.