AES_GCM on ATP-Series

Options
Tunox
Tunox Posts: 4 image  Freshman Member
First Comment Second Anniversary

Dear Zyxel-Team,

in the near Future a Phone-Provider we have an VPN Connection to, tolds me in December, that we urgently should update our Connection from AES_CBC to AES_GCM.

We use a ATP700 with the latest Update installed (5.41). Is there a Chance, that Zyxel provides GCM in an further Update ?

Thx

Gordon

Accepted Solution

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,532 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @Tunox

    After checking with our product team, the ATP series, also USG FLEX series, won't implement AES_GCM.

    If you have this requirement, we recommend migrating to USG FLEX H series.

    https://www.zyxel.com/global/en/products/next-gen-firewall/usg-flex-firewall-usg-flex-700h

    Zyxel Melen


  • mMontana
    mMontana Posts: 1,461 image  Guru Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers 1000 Comments

    Is available the technical reason why AES-GCM won't be implemented, as cypher, on Flex series?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,532 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @mMontana

    For ZLD (USG FLEX/ATP), we are not able to add AES-GCM-256 support, due to the fact that the underlying VPN turnkey does NOT support the algorithm and migrating to a newer version turnkey is not an option on this platform.

    Zyxel Melen


  • mMontana
    mMontana Posts: 1,461 image  Guru Member
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 50 Answers 1000 Comments

    …because the updated version of turnkey is available on newer devices, Flex H.

    I hope there won't be from third parties (like PCI-DSS) a "ban" for device having only AES_CBC as available protocol.
    Could hit some nerve at budget levels…