pjhtech Tools
Configuration & sysadmin

IKEv2 Proposal Checker

Check whether selected IKEv2 encryption and integrity choices fit together, and identify the setting to change.

Input

Reset restores the example inputs.

Local calculation · inputs are not sent to a server.

Result

Calculating the example…

Select the IKE encryption, separate integrity transform, PRF and DH group from your intended proposal. With AES-GCM, choose None for separate integrity. With AES-CBC or 3DES, select a separate integrity transform. Both cases still need a PRF.

Example: AES-GCM with no separate integrity, PRF SHA2-256 and group 19 is structurally consistent in this model. Adding a separate HMAC integrity transform to this AEAD selection is rejected.

Match the transforms and key lengths with the other peer. This checks the selected IKE SA fields; it does not connect to a VPN peer or check authentication, identities or ESP/Child-SA settings.

References