Component: ipsec
511 changelog entries across 207 version(s)
Releases by channel (stacked)
- ike2 improved process for policies;
- changed default dpd-interval from 2 minutes to 8 seconds and dpd-maximum-failures from 5 to 4;
- improved installed SA statistics update;
- fixed setting "static-dns" for mode configuration (introduced in v7.16beta1);
- improved installed SA statistics update;
- improved performance by balancing multicore CPU usage for key exchange calculation;
- improved performance by balancing multicore CPU usage;
- changed default dpd-interval from 2 minutes to 8 seconds and dpd-maximum-failures from 5 to 4;
- fixed Diffie-Hellman public value encoding size;
- fixed IPSec policy when using modp3072;
- fixed minor typo in logs;
- reduce disk writes when started without active configuration;
- fixed Diffie-Hellman public value encoding size;
- fixed minor typo in logs;
- reduce disk writes when started without active configuration;
- fixed IPSec policy when using modp3072;
- fixed IPSec policy when using modp3072;
- improved IKE2 rekey process;
- properly check ph2 approval validity when using IKE1 exchange mode;
- added hardware acceleration support for IPQ-5010 (hAP ax lite);
- refactor public key authentication;
- removed "ec2n185" and "ec2n155" values from proposal configurations;
- added hardware acceleration support for IPQ-5010 (hAP ax lite);
- removed "ec2n185" and "ec2n155" values from proposal configurations;
- added hardware acceleration support for IPQ-5010 (hAP ax lite);
- refactor public key authentication;
- added error log message when peer ID does not match certificate;
- fixed packet processing by hardware encryption engine on RB850Gx2 device;
- refactor X.509 implementation;
- added error log message when peer ID does not match certificate;
- improved handling of configuration that refers to non-existent certificate (introduced in v7.9beta4);
- fixed packet processing by hardware encryption engine on RB850Gx2 device;
- refactor X.509 implementation;
- added support for "Framed-Route" RADIUS attribute support;
- do not match incoming IKE requests by unresolved DNS name peers;
- fixed peer matcher for incoming connection with unresolved DNS;
- fixed peer matcher for incoming connection with unresolved DNS;
- added support for "Framed-Route" RADIUS attribute support;
- do not match incoming IKE requests by unresolved DNS name peers;
- added "current-address" parameter for peers with DNS address;
- added hardware acceleration support for IPQ-6010;
- added support for AVX optimized SHA acceleration;
- improved "H" (hw-aead) flag presence for accelerated SA's;
- improved IKE payload processing;
- improved configuration of IPsec proposal auth-algorithms;
- removed Blowfish and Camellia encryption algorithms for IKE;
- improved IKE payload processing;
- added "current-address" parameter for peers with DNS address;