cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
655
Views
0
Helpful
3
Replies

IPSEC SA Algorithm how many bit?

alberto-pesce
Beginner
Beginner

Hi all,

 how many bit for the IPSEC SA Algorithm on the ASA Version 8.2(1) ?

esp-md5-hmac
esp-sha-hmac

 

Best Regards

Alp

1 Accepted Solution

Accepted Solutions

Karsten Iwen
VIP Mentor VIP Mentor
VIP Mentor

It's 96 Bit based on RFC2403/2404.

View solution in original post

3 Replies 3

Karsten Iwen
VIP Mentor VIP Mentor
VIP Mentor

It's 96 Bit based on RFC2403/2404.

Perhaps important to add: If you use modern equipment you can run IKEv2 where more modern integrity algorithms are specified like SHA256.

(Theoretical it could also be used by older gear implementing IKEv1/IPSec, but at least for the ASA it's not done).

Need version 9 or above to run more advanced encryption and ikev2.  Can't use a sha256 hash with the older ASA models only the "X" models or above.  Best you can do is aes256-cbc with sha1 or md5 and of course no hash at all with the older devices.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers