<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AES-GCM support - IPsec Phase1 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203263#M33808</link>
    <description>&lt;P&gt;We are seeing more requests to move VPN's to IKEv2 and AEAD suites only as well.Let's hope this functionality is underway.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2024 06:21:11 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2024-01-17T06:21:11Z</dc:date>
    <item>
      <title>AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/175876#M29311</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Checking R80.40 or R81 VPN administration guide i only see AES-128/256 for Site-to-site IPsec Phase 1 configuration. I believe that implies CBC. How about support for AES-256GCM in Phase1? Is it possible to support it by upgrading to some specific version or by enabling support somewhere under the hood?&lt;/P&gt;&lt;P&gt;I am receiving requests to negotiate GCM for both phases and actually one of the S2S remote party says they are stopping CBC support for IPSec.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 09:09:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/175876#M29311</guid>
      <dc:creator>Vilius</dc:creator>
      <dc:date>2023-03-23T09:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/175879#M29312</link>
      <description>&lt;P&gt;At this point, we only support&amp;nbsp;&lt;SPAN&gt;AES-GCM ciphers with Phase 2. If you need then with Phase 1, please open an RFE.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 09:29:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/175879#M29312</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-23T09:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/188675#M31629</link>
      <description>&lt;P&gt;We are seeing more and more vendors requiring AES-GCM in Phase 1. Does Check Point have any documentation that explains why they chose not to support it? It would be great to have some ammunition to fire back.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 19:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/188675#M31629</guid>
      <dc:creator>Brad_Muller</dc:creator>
      <dc:date>2023-08-04T19:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/189582#M31788</link>
      <description>&lt;P&gt;There are references to CP implementation using and recommending NSA Suite-B cryptography. It is not helpful much, because Suite-B is now depreciated in favor of&amp;nbsp;Commercial National Security Algorithm Suite (CNSA).&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178705" target="_blank"&gt;Quantum Computing Recommended Site-to-Site VPN configuration (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I did submit RFE through CP representative. Last update is that we can expect full AES-GCM support with next major release in 2024. Given usual time frame for version to be recommended and corporate upgrade cycles, this will be an issue for foreseeable future.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 08:48:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/189582#M31788</guid>
      <dc:creator>Vilius</dc:creator>
      <dc:date>2023-08-16T08:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/190030#M31843</link>
      <description>&lt;P&gt;We are considering to add it, I will update soon.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Idan Tsarfati&lt;/P&gt;
&lt;P&gt;IPsec VPN &amp;nbsp;R&amp;amp;D group manager&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 19:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/190030#M31843</guid>
      <dc:creator>idants</dc:creator>
      <dc:date>2023-08-21T19:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/201139#M33535</link>
      <description>&lt;P&gt;Idan,&amp;nbsp; We have a case open for this now in December of 2023.. please let us know when AES-GCM will be part of the release.&amp;nbsp; I am at R81.20 and have a Site-to-Site tunnel that will be going down if we do not have GCM support for Phase 1.&amp;nbsp; We'll simply have to buy a competitive product, and I've been loyal to Check Point for almost 26 years.&amp;nbsp; Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 21:42:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/201139#M33535</guid>
      <dc:creator>pulidan</dc:creator>
      <dc:date>2023-12-19T21:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203263#M33808</link>
      <description>&lt;P&gt;We are seeing more requests to move VPN's to IKEv2 and AEAD suites only as well.Let's hope this functionality is underway.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 06:21:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203263#M33808</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-01-17T06:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203530#M33826</link>
      <description>&lt;P&gt;I have been informed that GCM ciphers will be supported for Phase 1 in R82.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 18:10:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203530#M33826</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-01-18T18:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: AES-GCM support - IPsec Phase1</title>
      <link>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203743#M33860</link>
      <description>&lt;P&gt;Correct, AES-GCM in phase will be supported in R82.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 14:16:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/AES-GCM-support-IPsec-Phase1/m-p/203743#M33860</guid>
      <dc:creator>idants</dc:creator>
      <dc:date>2024-01-21T14:16:37Z</dc:date>
    </item>
  </channel>
</rss>

