Component: ipsec
511 changelog entries across 207 version(s)
Releases by channel (stacked)
- fixed expired SA handling to prevent “no such item” errors during listing;
- improved aes256-ctr stability on L009;
- removed modp8192 proposal on MIPS architectures;
- improved NAT encapsulation parameter forwarding;
- added netlink-based SA and policy handling;
- fixed SA proto parameter conversion and policy "none" type handling;
- added "none" option to IPsec key QKD certificate field;
- added IKEv2 DDoS cookie activation setting;
- added logging for IPsec policy template group;
- added logging of IKEv2 connection SPI and initiator address;
- adjusted minimum generated PSK key length;
- fixed IKEv2 child policy reqid lost on rekey;
- fixed IKEv2 child reqid handling on traffic selector update;
- improved aes256-ctr stability on L009;
- removed modp8192 proposal on MIPS architectures;
- improved aes256-ctr stability on L009;
- removed modp8192 proposal on MIPS architectures;
- fixed CHACHA20 typo in log messages;
- support Post-Quantum Pre-shared Key (PPK) with QKD integration (CLI only);
- added "none" option to IPsec key QKD certificate field;
- added IKEv2 DDoS cookie activation setting;
- added logging for IPsec policy template group;
- added logging of IKEv2 connection SPI and initiator address;
- adjusted minimum generated PSK key length;
- fixed IKEv2 child policy reqid lost on rekey;
- fixed IKEv2 child reqid handling on traffic selector update;
- support Post-Quantum Pre-shared Key (PPK) with QKD integration (CLI only) (additional fixes);
- fixed CHACHA20 typo in log messages;
- support Post-Quantum Pre-shared Key (PPK) with QKD integration;
- fixed degraded IPsec performance for IPQ-6010 (introduced in v7.17);
- move raw RSA keys to /ip/ipsec/key/rsa;
- fixed responder on key exchange compute failure (introduced in v7.19);
- fixed responder on key exchange compute failure (introduced in v7.19);
- move raw RSA keys to /ip/ipsec/key/rsa;
- fixed degraded IPsec performance for IPQ-6010 (introduced in v7.17);
- fixed system failure on MMIPS devices when using IPsec services;
- lower standalone cipher, hash priority when using ctr aead;
- fixed system failure on MMIPS devices when using IPsec services;
- lower standalone cipher, hash priority when using ctr aead;
- added hardware acceleration support for hEX refresh;
- fixed chacha20 poly1305 proposal;
- fixed installed SAs update process when SAs are removed;
- added hardware acceleration support for hEX refresh (additional fixes);
- fixed chacha20 poly1305 proposal;
- fixed chacha20 poly1305 proposal;
- fixed installed SAs update process when SAs are removed;
- added hardware acceleration support for EN7562CT (hEX refresh);
- fixed installed SAs update process when SAs are removed;
- ike2 improved process for policies;