Description

Details regarding the support for HMAC SHA on vSRX device for ipsec vpn authentication algorithm

Symptoms

SHA512 option is not available under the below category,

[edit security ipsec proposal <name> authentication-algorithm]

Solution

Based on the IPsec settings enhancements on SRX TVP, High End and vSRX3.0, starting 23.4R1 releases, we can use HMAC-SHA-348 and HMAC-SHA-512 IPsec authentication algorithm under IPsec Settings for IKE Settings for Site-Site to VPN, NCP Exclusive Client and Juniper Secure Connect.

 

Details available below - https://www.juniper.net/documentation/us/en/software/junos/release-notes/23.4/junos-release-notes-23.4r1/topics/new-features/feature-descriptions/jweb-3.html

Modification History

2024-08-23 : Article Created