Hi,
I have a few questions about the existing encryption settings in R81.20.
We still have some communities using AES256 or AES128 and SHA1. We would like to improve security and are considering moving to:
Suite-B-GCM-256 default settings:
- AES-GCM-256
- SHA-384
- EC DH Group 20
Suite-B-GCM-128 default settings:
- AES-GCM-128
- SHA-256
- EC DH Group 19
I read but it's not clear to me.
sk73980 - Relative speeds of algorithms for IPsec and SSL
Solved: R80.x Performance Tuning Tip - AES-NI - Page 2 - Check Point CheckMates
Do both suites of protocols support AES-NI?
Also, are the same protocols used in Phase 1 and Phase 2 when using the pre-defined suites?
Do you have any other suggestions or recommendations?
Thank you,
Nicolas