BrotherJones
Technical User
just curious what the industry "best practices" was in regards to using Perfect Forward Secrecy. I notice a lot of other security devices ship with it enabled by default (and I understand that the reissuing of the DH keys everytime a new tunnel is established is more secure), but was just wondering if it is Best Practice to always try to use pfs or not?