- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- VPN Site to Site Encryption Suite Best Practise
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Site to Site Encryption Suite Best Practise
Any suggestions about the best performance/security parameters to use in a Site to Site Encryption Suite configuration ? I would stress the phase 1 and leave the phase 2 lighter....in few words
Phase 1
Encryption Alghoritm --> AES256
Data Integrity --> SHA256
DH Group --> Group14
Phase 2
Encryption Alghoritm --> 3DES
Data Integrity --> SHA1
unless the other side peer complain 🐵
What do you think about it ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Avoid 3DES as it's computationally inefficient compared to AES, and AES-NI will give you much better performance.
SHA1 shouldn't be used anymore in favor of AES256+
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Refer to sk105119 - Best Practices - VPN Performance and to sk104760 - ATRG: VPN Core. For a comparison of encryption algorithm speeds, refer to sk73980 - Relative speeds of algorithms for IPsec and SSL.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I recommend to differentiate between VPN Site-to-Site between Check Point gateways and with 3rd party VPN gateways.
Best practice settings (bold) for VPN with 3rd party gateways | Compatibility matrix
