- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
Hello,
Checking R80.40 or R81 VPN administration guide i only see AES-128/256 for Site-to-site IPsec Phase 1 configuration. I believe that implies CBC. How about support for AES-256GCM in Phase1? Is it possible to support it by upgrading to some specific version or by enabling support somewhere under the hood?
I am receiving requests to negotiate GCM for both phases and actually one of the S2S remote party says they are stopping CBC support for IPSec.
Thanks
At this point, we only support AES-GCM ciphers with Phase 2. If you need then with Phase 1, please open an RFE.
At this point, we only support AES-GCM ciphers with Phase 2. If you need then with Phase 1, please open an RFE.
We are seeing more and more vendors requiring AES-GCM in Phase 1. Does Check Point have any documentation that explains why they chose not to support it? It would be great to have some ammunition to fire back.
There are references to CP implementation using and recommending NSA Suite-B cryptography. It is not helpful much, because Suite-B is now depreciated in favor of Commercial National Security Algorithm Suite (CNSA). Quantum Computing Recommended Site-to-Site VPN configuration (checkpoint.com)
I did submit RFE through CP representative. Last update is that we can expect full AES-GCM support with next major release in 2024. Given usual time frame for version to be recommended and corporate upgrade cycles, this will be an issue for foreseeable future.
We are considering to add it, I will update soon.
Thanks,
Idan Tsarfati
IPsec VPN R&D group manager
Idan, We have a case open for this now in December of 2023.. please let us know when AES-GCM will be part of the release. I am at R81.20 and have a Site-to-Site tunnel that will be going down if we do not have GCM support for Phase 1. We'll simply have to buy a competitive product, and I've been loyal to Check Point for almost 26 years. Please advise.
Thanks,
Dan
We are seeing more requests to move VPN's to IKEv2 and AEAD suites only as well.Let's hope this functionality is underway.
I have been informed that GCM ciphers will be supported for Phase 1 in R82.
Correct, AES-GCM in phase will be supported in R82.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 22 | |
| 13 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 | |
| 7 |
Thu 12 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 3: AI-Generated Malware - From Experimentation to Operational RealityFri 13 Feb 2026 @ 10:00 AM (CET)
CheckMates Live Netherlands - Sessie 43: Terugblik op de Check Point Sales Kick Off 2026Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesThu 12 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 3: AI-Generated Malware - From Experimentation to Operational RealityFri 13 Feb 2026 @ 10:00 AM (CET)
CheckMates Live Netherlands - Sessie 43: Terugblik op de Check Point Sales Kick Off 2026Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY