- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello,
Checking R80.40 or R81 VPN administration guide i only see AES-128/256 for Site-to-site IPsec Phase 1 configuration. I believe that implies CBC. How about support for AES-256GCM in Phase1? Is it possible to support it by upgrading to some specific version or by enabling support somewhere under the hood?
I am receiving requests to negotiate GCM for both phases and actually one of the S2S remote party says they are stopping CBC support for IPSec.
Thanks
At this point, we only support AES-GCM ciphers with Phase 2. If you need then with Phase 1, please open an RFE.
At this point, we only support AES-GCM ciphers with Phase 2. If you need then with Phase 1, please open an RFE.
We are seeing more and more vendors requiring AES-GCM in Phase 1. Does Check Point have any documentation that explains why they chose not to support it? It would be great to have some ammunition to fire back.
There are references to CP implementation using and recommending NSA Suite-B cryptography. It is not helpful much, because Suite-B is now depreciated in favor of Commercial National Security Algorithm Suite (CNSA). Quantum Computing Recommended Site-to-Site VPN configuration (checkpoint.com)
I did submit RFE through CP representative. Last update is that we can expect full AES-GCM support with next major release in 2024. Given usual time frame for version to be recommended and corporate upgrade cycles, this will be an issue for foreseeable future.
We are considering to add it, I will update soon.
Thanks,
Idan Tsarfati
IPsec VPN R&D group manager
Idan, We have a case open for this now in December of 2023.. please let us know when AES-GCM will be part of the release. I am at R81.20 and have a Site-to-Site tunnel that will be going down if we do not have GCM support for Phase 1. We'll simply have to buy a competitive product, and I've been loyal to Check Point for almost 26 years. Please advise.
Thanks,
Dan
We are seeing more requests to move VPN's to IKEv2 and AEAD suites only as well.Let's hope this functionality is underway.
I have been informed that GCM ciphers will be supported for Phase 1 in R82.
Correct, AES-GCM in phase will be supported in R82.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY