Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Compatibility between aes-cbc-256 and aes-gcm-256 encryption.

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 3.6k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      ramses.sevilla
      last edited by

      Hi everyone,

      I need configure a VPN IPsec between a pfSense 2.4.5 and other Remote Firewall.

      The Admin from the Remote Site tell me that the Remote Firewall has configured aes-cbc-256 encryption but my pfSense 2.4.5 hasn't this encryption type.

      would It work if I configure aes-gcm-256 in my pfSense to connect to the Remote Firewall that has configured aes-cbc-256 encryption?

      Regards,

      Ramsés

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        The two are different, they can't work together. But you do have AES 256 on pfSense in IPsec. Select AES with a key length of 256.

        15bcc1bb-c88f-4acd-b171-25628542c77b-image.png

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • R Offline
          ramses.sevilla
          last edited by

          @jimp, thanks so much by your answer.

          Then if I configure in my pfSense:

          Encryption Algorithm:

          Algorithm: AES
          Key length: 256

          It can connect with the Remote Firewall that has configured aes-cbc-256 encryption?

          Regards,

          Ramsés

          1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate
            last edited by

            Yes, that is the same encryption.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 1
            • R Offline
              ramses.sevilla
              last edited by

              Thanks so much.

              Ramses

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.