Project

General

Profile

Actions

Bug #13368

closed

IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected

Added by Marcos M almost 2 years ago. Updated about 1 year ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
IPsec Profile Wizard
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

The following P1 cipher suite is supported by Windows natively, yet the wizard prevents it:

AES256-GCM | 128 bits | SHA384 | 20 (nist ecp384)

Phase 1 DH Group unsupported by this client. Supported values are (1, 2, 14, 19, 20, 24)

Switching the Algorithm from AES256-GCM to AES allows the wizard to export a profile.


Files


Related issues

Related to Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configurationResolvedJim Pingle

Actions
Related to Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"ResolvedJim Pingle

Actions
Actions

Also available in: Atom PDF