Skip to main content
Techniq808
New Member
August 2, 2018
Question

AES Block Cipher Modes

  • August 2, 2018
  • 2 replies
  • 8029 views

Does anyone know the default AES block cipher mode used (GCM, CBC, CTR, etc) for IPSec VPN Phase I/II?

 

And is this configurable/modifiable?

 

Thanks in advance.

    2 replies

    emnoc
    New Member
    August 2, 2018

    It should be cbc ,  what version are you  working with ( fortios ) and have you  looked at the cli reference guide ?

     

     

    ispcolohost
    New Member
    August 2, 2018

    Later FortiOS versions allow you to select GCM for phase2 but you must explicitly select it.  If you don't see those in the drop down for the p2 config, your version is not new enough.  You can also select CHACHA20POLY1305 for the p2.  Now, that being said, I have a feeling you'll only gain from making this selection if you're running on a box with a new enough CPU that has the AES-NI instruction set.  I was about to post a thread asking about this actually, since the FortiOS docs aren't clear.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!