Skip to content

Commit f93b38a

Browse files
authored
Merge pull request #79336 from anzaman/master
IKE and TLS policies
2 parents eabbfda + ed1fe31 commit f93b38a

File tree

1 file changed

+62
-0
lines changed

1 file changed

+62
-0
lines changed

articles/vpn-gateway/point-to-site-about.md

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,68 @@ The zip file also provides the values of some of the important settings on the A
8282
>The Basic SKU does not support IKEv2 or RADIUS authentication.
8383
>
8484
85+
## <a name="IKE/IPsec policies"></a>What IKE/IPsec policies are configured on VPN gateways for P2S?
86+
87+
88+
**IKEv2**
89+
90+
|**Cipher** | **Integrity** | **PRF** | **DH Group** |
91+
|--- | --- | --- | --- |
92+
|GCM_AES256 | GCM_AES256 | SHA384 | GROUP_24 |
93+
|GCM_AES256 | GCM_AES256 | SHA384 | GROUP_14 |
94+
|GCM_AES256 | GCM_AES256 | SHA384 | GROUP_ECP384 |
95+
|GCM_AES256 | GCM_AES256 | SHA384 | GROUP_ECP256 |
96+
|GCM_AES256 | GCM_AES256 | SHA256 | GROUP_24 |
97+
|GCM_AES256 | GCM_AES256 | SHA256 | GROUP_14 |
98+
|GCM_AES256 | GCM_AES256 | SHA256 | GROUP_ECP384 |
99+
|GCM_AES256 | GCM_AES256 | SHA256 | GROUP_ECP256 |
100+
|AES256 | SHA384 | SHA384 | GROUP_24 |
101+
|AES256 | SHA384 | SHA384 | GROUP_14 |
102+
|AES256 | SHA384 | SHA384 | GROUP_ECP384 |
103+
|AES256 | SHA384 | SHA384 | GROUP_ECP256 |
104+
|AES256 | SHA256 | SHA256 | GROUP_24 |
105+
|AES256 | SHA256 | SHA256 | GROUP_14 |
106+
|AES256 | SHA256 | SHA256 | GROUP_ECP384 |
107+
|AES256 | SHA256 | SHA256 | GROUP_ECP256 |
108+
|AES256 | SHA256 | SHA256 | GROUP_2 |
109+
110+
**IPsec**
111+
112+
|**Cipher** | **Integrity** | **PFS Group** |
113+
|--- | --- | --- |
114+
|GCM_AES256 | GCM_AES256 | GROUP_NONE |
115+
|GCM_AES256 | GCM_AES256 | GROUP_24 |
116+
|GCM_AES256 | GCM_AES256 | GROUP_14 |
117+
|GCM_AES256 | GCM_AES256 | GROUP_ECP384 |
118+
|GCM_AES256 | GCM_AES256 | GROUP_ECP256 |
119+
| AES256 | SHA256 | GROUP_NONE |
120+
| AES256 | SHA256 | GROUP_24 |
121+
| AES256 | SHA256 | GROUP_14 |
122+
| AES256 | SHA256 | GROUP_ECP384 |
123+
| AES256 | SHA256 | GROUP_ECP256 |
124+
| AES256 | SHA1 | GROUP_NONE |
125+
126+
## <a name="TLS policies"></a>What TLS policies are configured on VPN gateways for P2S?
127+
**TLS**
128+
129+
|**Policies** |
130+
|---|
131+
|TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 |
132+
|TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 |
133+
|TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
134+
|TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
135+
|TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 |
136+
|TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 |
137+
|TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 |
138+
|TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 |
139+
|TLS_RSA_WITH_AES_128_GCM_SHA256 |
140+
|TLS_RSA_WITH_AES_256_GCM_SHA384 |
141+
|TLS_RSA_WITH_AES_128_CBC_SHA256 |
142+
|TLS_RSA_WITH_AES_256_CBC_SHA256 |
143+
144+
145+
146+
85147
## <a name="configure"></a>How do I configure a P2S connection?
86148

87149
A P2S configuration requires quite a few specific steps. The following articles contain the steps to walk you through P2S configuration, and links to configure the VPN client devices:

0 commit comments

Comments
 (0)