<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HMAC support on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051818#M1068183</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Whatever is part of the Suite B (Next Generation Algorithms), including what you're asking for, is only supported on the ASA for IPsec tunnels build over IKEv2, so not for IPsec tunnel over IKEv1. With IKEv2 IPsec tunnels, you can use the Suite B algorithms for both the IKEv2 and IPsec tunnel (or only for one, you choose), while with IKEv1 IPsec tunnels, you can't use Suite B algorithms for IKEv1 or IPsec tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Mar 2020 07:33:30 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2020-03-25T07:33:30Z</dc:date>
    <item>
      <title>HMAC support on ASA</title>
      <link>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051766#M1068175</link>
      <description>&lt;P&gt;How can I tell if may ASA 5525-X supports the following:&lt;/P&gt;&lt;P&gt;hmac-sha2-256&lt;BR /&gt;hmac-sha2-384&lt;BR /&gt;hmac-sha2-512&lt;BR /&gt;and if it does how do I enable it. My software ver is :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.7(1)24&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 03:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051766#M1068175</guid>
      <dc:creator>bruce.thornton</dc:creator>
      <dc:date>2020-03-25T03:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: HMAC support on ASA</title>
      <link>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051777#M1068177</link>
      <description>&lt;P&gt;For IKEv2 you can configure the HMAC-SHA2 variants:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/configuration/vpn/asa-913-vpn-config/vpn-ike.html#ID-2441-000005d2" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/configuration/vpn/asa-913-vpn-config/vpn-ike.html#ID-2441-000005d2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/p3.html#pgfId-2175641" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/p3.html#pgfId-2175641&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;IKEv1 is limited to SHA/HMAC-160 (or MD5/HMAC-128)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/c5.html#pgfId-2607523" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/c5.html#pgfId-2607523&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 04:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051777#M1068177</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-25T04:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: HMAC support on ASA</title>
      <link>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051818#M1068183</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Whatever is part of the Suite B (Next Generation Algorithms), including what you're asking for, is only supported on the ASA for IPsec tunnels build over IKEv2, so not for IPsec tunnel over IKEv1. With IKEv2 IPsec tunnels, you can use the Suite B algorithms for both the IKEv2 and IPsec tunnel (or only for one, you choose), while with IKEv1 IPsec tunnels, you can't use Suite B algorithms for IKEv1 or IPsec tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 07:33:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hmac-support-on-asa/m-p/4051818#M1068183</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-25T07:33:30Z</dc:date>
    </item>
  </channel>
</rss>

