Skip to main content

Using IPsec to protect data

Guidance for organisations wishing to deploy products that use IPsec.

This guidance provides recommendations for the selection and configuration of equipment that uses IPsec. It also describes how a network encryption service using IPsec should be designed, operated and maintained to provide a level of security appropriate for protecting personal, enterprise and OFFICIAL-tier government information. The recommendations in this guidance address both security and usability.


Note

This guidance (and IPsec itself) makes no assumptions about the underlying security or resilience of the bearer network. Therefore, any bearer network can be used without affecting the confidentiality or integrity protection provided by the IPsec VPN.



Certificate algorithms and key sizes

For most IPsec-based networks, VPN gateways and clients will need to use certificates based on a central trust infrastructure to successfully identify themselves to other VPN devices. Both the Recommended and Legacy Profiles use X.509 certificates to authenticate peers. This is achieved using either the ECDSA or RSA digital signature algorithm.

The parameters for each algorithm, for root CAs, sub-CAs, and end entity devices are:

  • ECDSA with SHA256 digests on NIST P-256 curve
  • RSA with 2048-bit modulus and SHA256 digests

For RSA signature algorithms, both RSASSA-PSS and RSASSA-PKCS1-v1_5 are acceptable, with RSASSA-PKCS1-v1_5 being more generally supported (RFC 7427, RFC 8017).

Both ECDSA and RSA, with the above parameters, are expected to provide a suitable level of protection for OFFICIAL information until at least 31st December 2027.

The NCSC has guidance on how to Design and build a privately hosted Public Key Infrastructure.

Recommended Profile

For configuring IKE, the Recommended Profile uses the following parameters:

ParameterSelectionRFCs
IKE VersionIKEv2RFC7296
Encryption AlgorithmAES with 128-bit key using GCM with 16-octet (128-bit) tagsRFC5282
Pseudo-Random FunctionHMAC-SHA-256RFC4868
Diffie-Hellman Group256-bit random ECP Group 19 or 2048-bit MODP Group 14RFC5903, RFC3526
Authentication MethodX.509 certificates using ECDSA or RSARFC4945, RFC4754, RFC4055

For configuring Encapsulating Security Payload (ESP), the Recommended Profile uses the following parameters:

ParameterSelectionRFCs
Encryption AlgorithmAES with 128-bit key using GCM with 16-octet (128-bit) tagsRFC4106

For configuring key lifetimes, the Recommended Profile uses the following lifetimes:

Key TypeLifetime
IKE SA86,400 seconds (1 day)
Child SA28,800 seconds (8 hours)

The Recommended Profile is expected to provide a suitable level of protection for OFFICIAL information until at least 31st December 2027.

Legacy Profile

With the development of IKEv2, there have been no updates to IKEv1 for over a decade which means that IKEv1 does not support current cipher suites. Implementations also run the risk of using unmaintained code bases, meaning that any security vulnerabilities are unlikely to be patched. IKEv1 has been formally deprecated by the IETF (RFC 9395) and moved to Historic status, so the NCSC strongly advises that IKEv1, and this legacy profile, should no longer be used.

A time-bounded migration plan should be put in place for any government systems still using the deprecated IKEv1 to move to IKEv2. Where this is not possible, system owners should approach the NCSC for advice.

The following legacy profile is defined only for use cases where IKEv1 cannot yet be disabled. It consists of an RFC 2409-compliant implementation of IPsec with IKEv1 using 'Main Mode', without custom extensions, using Extended Sequence Numbers (RFC4304), Encapsulating Security Payload (ESP) (RFC4303), and the algorithms given in the tables below.

For configuring IKE, the Legacy Profile uses the following parameters:

ParameterSelectionRFCs
IKE VersionIKEv1RFC2409
ModeMain ModeRFC2409
Encryption AlgorithmAES with 128-bit key using CBCRFC3602
Hash AlgorithmSHA2-256RFC4868
Diffie-Hellman Group256-bit random ECP Group 19 or 2048-bit MODP Group 14RFC5903, RFC3526
IKE Authentication MethodX.509 certificates using ECDSA or RSARFC4945, RFC4754, RFC4055

Note

The use of Main Mode is mandatory. No other mode is acceptable.

For configuring Encapsulating Security Payload (ESP), the Legacy Profile uses the following parameters:

ParameterSelectionRFCs
Encryption AlgorithmAES with 128-bit key using CBCRFC3602
Integrity AlgorithmHMAC-SHA-256-128RFC4868

Some currently fielded devices are unable to use HMAC-SHA-256-128 for the ESP integrity algorithm. In accordance with wider recommendations on the use of SHA-1, you can continue to use HMAC-SHA-1-96 as the ESP integrity algorithm at this time. SHA-1 must not be used for any other purpose within IPsec.

For configuring key lifetimes, the Legacy Profile uses the following lifetimes:

Key TypeLifetime
Phase 1

86,400 seconds (1 day)

Phase 228,800 seconds (8 hours)

It is acceptable to replace any element of the Legacy Profile with the corresponding element from the Recommended Profile.

You should no longer rely on the Legacy Profile to provide a suitable level of protection for OFFICIAL information.

Security considerations for key exchanges

Some IPsec equipment may re-use ephemeral Diffie-Hellman private keys with multiple IKE SAs. If such equipment can be configured to do so, we recommend that ephemeral Diffie-Hellman private keys are only ever used by a single IKE SA.

Published

Reviewed

Version

2.1