Specifies which encryption algorithms are enabled in the Child-SA.
- SNMP ID:
- 2.19.36.2.6
- Console path:
- Setup > VPN > IKEv2 > Encryption
- Possible values:
- AES-CBC-256
- AES-CBC-192
- AES-CBC-128
- 3DES
- AES-GCM-256
- Advanced Encryption Standard (AES) 256 in Galois / Counter Mode (GCM)
- AES-GCM-192
- Advanced Encryption Standard (AES) 192 in Galois / Counter Mode (GCM)
- AES-GCM-128
- Advanced Encryption Standard (AES) 128 in Galois / Counter Mode (GCM)
- Chacha20-Poly1305
-
ChaCha20 data stream encryption in conjunction with the Poly1305 Authenticator, see RFC 7634, will be supported from LCOS version 10.40.
Important: Please note that ChaCha20-Poly1305 is currently not accelerated by hardware and is therefore not recommended for VPN scenarios where high encryption performance is required.
- Default:
- AES-CBC-256
- AES-GCM-256