Component: ipsec
511 changelog entries across 207 version(s)
Releases by channel (stacked)
- added aes-gcm icv16 encryption mode;
- added aes-ctr encryption mode;
- added sha256 and sha512 support;
- proposal defaults changed to aes-128 and sha1 for both phase1 and phase2;
- fix policy bypass on IPv6 gre, ipip, eoip tunnels when policy uses protocol filter;
- fix peer mathing with non byte aligned masks;
- fixed peer address matching;
- fix phase1 autonegotiation on little endian platforms;
- for peers with full IP address specified system will autostart ISAKMP SA negotiation;
- added /peer passive option which will prevent starting ISAKMP negotiation and signifies xauth responder/initiator side;
- added pre-shared-key-xauth and rsa-signature-hybrid authentication methods;
- support authorization with raw RSA keys;
- new exchange mode (main-l2tp) for l2tp tunnel users to allow FQDN as a peer ID with preshared key authorization in main mode;
- fixed problem of RB1200 rebooting when large amount of UDP traffic is sent through IPsec;