- perfect-forward-secrecy
keys (group1 | group2 | group5);
- [edit security ipsec policy policy-name ]
Statement modified in Release 8.5 of JUNOS software.
Specify Perfect Forward Secrecy (PFS) as the method that the device uses to generate the encryption key. PFS generates each new encryption key independently from the previous key.
This statement is supported on J-series and SRX-series devices.
group1—Diffie-Hellman Group 1.
group2—Diffie-Hellman Group 2.
group5—Diffie-Hellman Group 5.
For configuration instructions and examples, see the JUNOS Software Security Configuration Guide.
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.