Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    IPSec with AES-256-GCM key length

    IPsec
    2
    4
    129
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mstoebich last edited by

      So we are in the process of setting up a VPN to a customer. Their requirement is ipsec with AES-256-GCM and a key length of 256. If i look at my options inside the VPN/ipsec tab, I can't find a key length of 256 bits, the dropdown only shows 128-,96- and 64-bit key lengths when using AES-256-GCM.
      After some googeling this gets even more confusing. Doesn't the 256 in AES-256-GCM tell the key length? But then why can i even change it on my pfsense? and why only to these three lower values?

      Also: maybe this isn't the keylength, but the block size?

      I can't wrap my head around that.

      1 Reply Last reply Reply Quote 0
      • jimp
        jimp Rebel Alliance Developer Netgate last edited by

        AES-256-GCM is a 256-bit key length. The other selector there, in the case of AES-GCM, is the ICV, not a key length.

        1 Reply Last reply Reply Quote 0
        • M
          mstoebich last edited by

          Thanks for the answer, I've figured that out a few days ago and totally forgot to mention it here (shame on me)...

          So this dropdown doesn't always 'behave' the same way?

          1 Reply Last reply Reply Quote 0
          • jimp
            jimp Rebel Alliance Developer Netgate last edited by

            AES-GCM is the only exception to the way the drop-down works.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post

            Products

            • Platform Overview
            • TNSR
            • pfSense
            • Appliances

            Services

            • Training
            • Professional Services

            Support

            • Subscription Plans
            • Contact Support
            • Product Lifecycle
            • Documentation

            News

            • Media Coverage
            • Press
            • Events

            Resources

            • Blog
            • FAQ
            • Find a Partner
            • Resource Library
            • Security Information

            Company

            • About Us
            • Careers
            • Partners
            • Contact Us
            • Legal
            Our Mission

            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

            Subscribe to our Newsletter

            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

            © 2021 Rubicon Communications, LLC | Privacy Policy