- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have a few questions about the existing encryption settings in R81.20.
We still have some communities using AES256 or AES128 and SHA1. We would like to improve security and are considering moving to:
Suite-B-GCM-256 default settings:
Suite-B-GCM-128 default settings:
I read but it's not clear to me.
sk73980 - Relative speeds of algorithms for IPsec and SSL
Solved: R80.x Performance Tuning Tip - AES-NI - Page 2 - Check Point CheckMates
Do both suites of protocols support AES-NI?
Also, are the same protocols used in Phase 1 and Phase 2 when using the pre-defined suites?
Do you have any other suggestions or recommendations?
Thank you,
Nicolas
As far as I know, they should be covered in AES-NI and even handled in SecureXL.
Assuming the processor architecture of your appliance supports AES-NI, yes you want to use the GCM variants of AES for IPSec Phase 2. Use of the AES-GCM variants is supported both by SecureXL (in the fastpath) and the Firewall Worker cores (Medium & slowpath). Here are the relevant pages from my Gateway Performance Optimization course explaining this:
As far as I know, they should be covered in AES-NI and even handled in SecureXL.
Assuming the processor architecture of your appliance supports AES-NI, yes you want to use the GCM variants of AES for IPSec Phase 2. Use of the AES-GCM variants is supported both by SecureXL (in the fastpath) and the Firewall Worker cores (Medium & slowpath). Here are the relevant pages from my Gateway Performance Optimization course explaining this:
Thank you
Really clear !
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY