This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec AES256: CBC or GCM?

Hi,

is XG using CBC oder GCM with AES256 encryption and IPsec? Couldn't find anything about it.

Thanks.



This thread was automatically locked due to age.
Parents Reply
  • CBC seems to be the preferred cipher with Cisco VPN/Sophos Connect. Is there a reason GCM is not used? GCM is a modern and faster cipher?

    console> show vpn connection status
    [154]: IKEv1 SPIs:
    [154]: IKE proposal: AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048
    {91}: AES_CBC_256/HMAC_SHA1_96

    Sophos Connect

Children
  • Sophos Connect uses IKEv1 and Remote Access IPsec. 

     

    I cannot comment on this at all, i do not have a IKEv2 Tunnel right now to verify, which Method is used. 

    __________________________________________________________________________________________________________________