Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC chachapoly support, windows clients parameters?

    CE 2.7.0 Development Snapshots (Retired)
    2
    4
    644
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • perikoP
      periko
      last edited by

      Hello guys.

      The new cipher for IPSEC Chachapoly:

      Support for ChaCha20-Poly1305 encryption with IPsec
      

      I want to setup EAP-MSCHAPv2 and EAP-TLS but would like to know the settings to use with this new cipher under IPSEC?

      pfsense-2-5.png

      Any help will be appreciated, thanks!!!

      Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
      www.bajaopensolutions.com
      https://www.facebook.com/BajaOpenSolutions
      Quieres aprender PfSense, visita mi canal de youtube:
      https://www.youtube.com/c/PedroMorenoBOS

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        As far as I'm aware, Windows doesn't support ChaCha20-Poly1305 for IPsec yet.

        If it did, it would be listed in their docs for configuring VPN parameters:

        https://learn.microsoft.com/en-us/powershell/module/vpnclient/set-vpnconnectionipsecconfiguration

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        perikoP 1 Reply Last reply Reply Quote 2
        • perikoP
          periko @jimp
          last edited by

          @jimp I was thinking that maybe Windows will be limited about this, them ipsec site to site between 2 pfsense boxes could benefit from this new feauture.
          Thanks master.

          Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
          www.bajaopensolutions.com
          https://www.facebook.com/BajaOpenSolutions
          Quieres aprender PfSense, visita mi canal de youtube:
          https://www.youtube.com/c/PedroMorenoBOS

          1 Reply Last reply Reply Quote 1
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Yes, it does work pfSense <-> pfSense and also with TNSR (TNSR <-> TNSR and TNSR <-> pfSense).

            It may not be any faster than AES-GCM depending on your setup but the only way to know for sure is to test it on your own hardware, environment, and workload.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.