Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CaseyB
Advisor

PSA: Check Point and Palo Alto - GCM Phase 1

Upgrading to R82 allows the use of GCM ciphers in Phase 1. If you were as excited as I, you might have tried to use them already and you might have had issues getting it to work with Palo Alto. This topic is for you!

How to define Pseudo Random Functions in the VPN community - According to this 7-year-old SK, you would assume that Check Point would send PRF-256 for AES-GCM-256 for Phase 1, this is not the case. Check Point sends PRF-384 for AES-GCM-256 in Phase 1, this is confirmed by debugs & TAC. Maybe there is a newer SK? I submitted feedback for that SK article.

Per Palo documentation - If you select an AES-GCM algorithm for encryption, you must select the Authentication setting non-auth or the commit will fail. The hash is automatically selected based on the DH Group selected. DH Group 19 and below uses sha256; DH Group 20 uses sha384.

So, for AES-GCM-256 in Phase 1 to work between Check Point and Palo Alto, you need to use at least Group 20. Group 19 and below will fail due to issues with PRF differences.

(1)
5 Replies
PhoneBoy
Admin
Admin

Good to know!

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Thanks for that @CaseyB . Its been some time since I worked on PAN fws, but I believe they dont even let you configure domain based tunnels any more, its all route based.

FWIW, I see most vendors now go with at least DH group 14, so definitely good for security.

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
CaseyB
Advisor

This tunnel is still policy based, they did not ask about moving to route based.

My curiosity had me testing AES-GCM-128 this morning, it also is using PRF-384.

the_rock
MVP Diamond
MVP Diamond

Fair enough. I just mentioned route based, since it appears that seems to be the future : - )

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
BAlexiev
Participant

Hi, Casey, although this was one year ago, could you elaborate on your testing environment, including if it is using Gaia or it is a Spark with Gaia Embedded?

According to the R82 documentation (Spark edition, as we have clear selections there), we may use Suite-B GCM-128 or Suite-B-GCM-256 - According to RFC 6379. And the RFC mandates the use of HMAC-SHA-256 for GCM-128 and HMAC-SHA-384 for GCM-256. This is because ECP256 hash has 128-bit security and ECP384 has 192-bit security.

So, it would be a bit strange if AES-GCM-128 is using PRF-384, maybe it depends on your settings. But it is a possible custom combination.

Bobby
CCSE R82
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events