Select the DH Group to use for the IPSec SA negotiations in IKE phase 2.
From DH Group, select the key strength you want to
use: group1, group2,
group5, group14,
group15, group16,
group19, group20, or
group21. For the highest security, choose the
group with the highest number.
Beginning with PAN-OS 10.2.0 and later releases,
group15, group16, and
group21 Diffie-Hellman (DH) groups are
supported.
If you don’t want to renew the key that the firewall creates during IKE phase
1, select no-pfs (no perfect forward secrecy); the
firewall reuses the current key for the IPSec security association (SA)
negotiations.