Supported cipher suites for IPsec

In the IPsec protocol suite, Internet Key Exchange (IKE) is the protocol that’s used to establish and manage security associations (SAs) between your enterprise appliance (SD-WAN device or router) and ​SIA​ Proxy. The Encapsulating Security Payload (ESP) protocol provides confidentiality, data origin authentication, integrity, and protection from replay attacks.

The following tables list the cipher suites that ​SIA​ supports for these protocols.

Supported cipher suites for IKE protocol

Cipher SuiteDiffie-Hellman (DH) GroupEncryption AlgorithmIntegrity Algorithm
aes256gcm16-sha384-ecp38420AES-GCM-256SHA2-384
aes128gcm16-sha256-ecp25619AES-GCM-128SHA2-256
aes256-sha256-ecp38420AES-CBC-256SHA2-256
aes256-sha256-ecp25619AES-CBC-256SHA2-256
aes256-sha512-modp409616AES-CBC-256SHA2-512
aes256-sha512-modp307215AES-CBC-256SHA2-512
aes256-sha512-modp204814AES-CBC-256SHA2-512
aes256-sha384-modp409616AES-CBC-256SHA2-384
aes256-sha384-modp307215AES-CBC-256SHA2-384
aes256-sha384-modp204814AES-CBC-256SHA2-384
aes256-sha256-modp409616AES-CBC-256SHA2-256
aes256-sha256-modp307215AES-CBC-256SHA2-256
aes256-sha256-modp204814AES-CBC-256SHA2-256

Supported cipher suites for ESP protocol

Cipher SuiteDH GroupEncryption AlgorithmIntegrity Algorithm
aes256-sha256-ecp38420AES-CBC-256SHA2-256
aes256-sha256-ecp25619AES-CBC-256SHA2-256
aes256-sha512-modp409616AES-CBC-256SHA2-512
aes256-sha512-modp307215AES-CBC-256SHA2-512
aes256-sha512-modp204814AES-CBC-256SHA2-512
aes256-sha384-modp409616AES-CBC-256SHA2-384
aes256-sha384-modp307215AES-CBC-256SHA2-384
aes256-sha384-modp204814AES-CBC-256SHA2-384
aes256-sha256-modp409616AES-CBC-256SHA2-256
aes256-sha256-modp307215AES-CBC-256SHA2-256
aes256-sha256-modp204814AES-CBC-256SHA2-256