This file list all supported MyIKEv2 crypto and its value in the test setup file
IKE SA Encryption
3desaes-cbc:<keylen>AES-CBC; when configure this in setup file, a key length suffix is also needed; e.g. aes-cbc:128 means AES-CBC with 128bit key lengthaes-gcm-16:<keylen>: AES-GCM with 16 bytes authentication tagaes-gcm-12:<keylen>: AES-GCM with 12 bytes authentication tagchacha20-poly1305
IKE SA Integrity
md5-96: MD5sha1-96: SHA1sha256: SHA256sha384: SHA384sha512: SHA512
IKE SA PRF
md5: MD5sha1: SHA1sha256: SHA256sha384: SHA384sha512: SHA512
ESP/Fastpath Encryption
null3desaes-cbc:<keylen>AES-CBC; when configure this in setup file, a key length suffix is also needed; e.g. aes-cbc:128 means AES-CBC with 128bit key lengthaes-gcm-16:<keylen>: AES-GCM with 16 bytes authentication tagaes-gcm-12:<keylen>: AES-GCM with 12 bytes authentication tagchacha20-poly1305
Diffie-Hellman Group
1/2/5/14/15/16/17/18/19/20/21/31
PKI Key Type
- RSA
- with
myikev2 createpkigenerated key:- CA: 4096bit
- EE: 2048bit
- Other source:
- any
- with
- ECDSA with following curves:
- with
myikev2 createpkigenerated key:- CA: P521
- EE: P384
- Other source:
- P224/P256/P384/P521
- with
- Ed25519