cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
747
Views
0
Helpful
3
Replies

IPSEC SA Algorithm how many bit?

alberto-pesce
Level 1
Level 1

Hi all,

 how many bit for the IPSEC SA Algorithm on the ASA Version 8.2(1) ?

esp-md5-hmac
esp-sha-hmac

 

Best Regards

Alp

1 Accepted Solution

Accepted Solutions

It's 96 Bit based on RFC2403/2404.

View solution in original post

3 Replies 3

It's 96 Bit based on RFC2403/2404.

Perhaps important to add: If you use modern equipment you can run IKEv2 where more modern integrity algorithms are specified like SHA256.

(Theoretical it could also be used by older gear implementing IKEv1/IPSec, but at least for the ASA it's not done).

Need version 9 or above to run more advanced encryption and ikev2.  Can't use a sha256 hash with the older ASA models only the "X" models or above.  Best you can do is aes256-cbc with sha1 or md5 and of course no hash at all with the older devices.