The Diffie-Hellman group chosen for key exchange during IKE Phase 1 (Main Mode) in a custom IPsec/IKE policy, such as DHGroup24 or DHGroup14.
Also called Diffie-Hellman group.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DH group in context, with comparison tables and the common traps.
Terms in this definition
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - IKE
Negotiates keys for IPsec tunnels. Site-to-site VPN connections in Azure rely on it together with IPsec, and Basic policy-based gateways support only the older IKEv1.
- Custom IPsec/IKE policy
Set of algorithms for IKE Phase 1 and IPsec Phase 2, together with DH and PFS groups and SA lifetimes, applied to one connection rather than the gateway; each connection takes one policy, and every parameter has to be filled in.
Related terms
- New-AzIpsecPolicy
Cmdlet in Az.Network for defining a custom IPsec/IKE policy on a connection, covering IKE encryption and integrity, DH group, IPsec encryption and integrity, PFS group, and SA lifetime and size.
- PFS group
Perfect Forward Secrecy group, the Diffie-Hellman group applied in IPsec Quick Mode (Phase 2). A frequent reason for tunnels failing on policy mismatch is PFS being on at one end only.