#ipsec
Just opened a Microsoft support case for IPsec. It's not actually for an IPsec issue, but those are the smartest oldheads left over there, and they'll probably just figure it out so they don't have to take another call about IPsec.
June 16, 2026 at 7:50 PM
Disabling crypto is a real (I think deprecated) feature in IPsec! Those guys thought of everything
September 24, 2026 at 1:58 AM
Soon I'm going to be posting about the journey of deploying IPsec isolation of clients to a production network. RDP, SMB, etc. So stay tuned.
March 1, 2025 at 7:50 PM
All we have to do to silence our detractors is to make the fastest PQC VPN in the universe, which is also hardware accelerated, and uses no battery, requires no configuration, is completely open source and standardized, and is wireguard and IPsec compatible.

To be fair that’s a pretty good plan
September 24, 2026 at 1:56 AM
A company will spend millions of dollars to insert network IPS rather than implement default deny firewall and scoped IPsec that makes the endpoints entirely immune. You don't even need to patch them, because you cannot talk to them. But it's easier to spend millions than architect. That is the gap.
January 17, 2025 at 11:40 PM
IPFire #Linux Firewall Gets Post-Quantum Cryptography Support for IPsec Tunnels 9to5linux.com/ipfire-linux...

#OpenSource
IPFire Linux Firewall Gets Post-Quantum Cryptography Support for IPsec Tunnels - 9to5Linux
IPFire 2.29 Core Update 193 Linux firewall distribution is now available for download with post-quantum cryptography support for IPsec tunnels
9to5linux.com
April 9, 2025 at 4:15 PM
I mean if you were in IPSec support you'd probably love getting non-IPSec tickets. It's like a mini-vacation.
June 16, 2026 at 8:53 PM
CVE-2026-43284 - Dirty Frag Linux kernel local privilege escalation vulnerability mitigation

On Ubuntu and Debian its normally disabled by default !

> sudo ipsec status
> sudo ipsec down <connection_name>
May 8, 2026 at 9:57 PM
Yeah so it turns out you can set up an IPsec tunnel but you can't actually talk through it thanks Palo Alto you're super bros in security I can't exactly explain
July 13, 2026 at 12:36 PM
I've been operating under the assumption my Team Lead was misunderstanding some deep network minutia for IPsec, which I'm the actual SME on. It would not conceivably operate how he describes.
He was right. There's a third non-encapsulation mode in a screen I haven't been in over a year. God damn it.
June 22, 2026 at 9:06 PM
Cloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet. https://cfl.re/3Oz67xN
Post-quantum encryption for Cloudflare IPsec is generally available
This post explains how we implemented the new hybrid IPsec handshake, why it took four years longer to land than its TLS counterpart, and how the industry is finally consolidating around a standard that works at Internet scale.
blog.cloudflare.com
April 30, 2026 at 1:05 PM
I mean "why is there a special IPSec AEAD in the kernel wired up to splice() and why is that enabled by default in everyone's kernel" complexity.
April 29, 2026 at 11:17 PM
If this had got prod it would be carnage. Luckily I went on a lark of a new 1:1 mirror of all GPOs and an isolated OU, where this only hit two machines. It's possibly something to do with IPsec or an incomplete policy clone. Digging in...
February 20, 2025 at 9:00 PM
Learn how an IPsec tunnel is deployed in production — NAT traversal, site-to-site setup, and securing LDAP/Kerberos traffic.

#solideinfo #ipsec #networksecurity #cybersecurity #packprotv #solidpax
IPsec Tunnel Architecture in Production Enterprise Environments
Learn how an IPsec tunnel is deployed in production — NAT traversal, site-to-site setup, and securing LDAP/Kerberos traffic.
solideinfo.com
September 25, 2026 at 8:27 AM
توضیح تکمیلی اینکه سیسکو کلاینت هست و پروتکل ipsec یا ssl و روی سرور نصب میشه و برای رفع فیلتر باید روی سرور خارج نصب بشه. بنابراین جناب دکتر دروغ میگه!
در راستای سیم کارت سفید یه دکتری سیمکارتش سفید بود نوشته بود اشتراک سه ماهه Cisco anyconnect میخرم به ۸۵۰ تومن. برای اونه! باور کنیم؟!
November 25, 2025 at 11:31 AM
Agora eu aprendi mais sobre ipsec do que gostaria
No fim aprendi mais sobre iptables do que gostaria
January 3, 2026 at 10:46 PM
Optimize IPsec tunnels with SD-WAN and ZTNA — learn how zero trust network access reshapes enterprise security beyond traditional site-to-site VPN.

#solideinfo #ipsec #ztna #sdwan #solidpax
Optimizing IPsec Tunnels with ZTNA and SD-WAN for Modern Network Security
Optimize IPsec tunnels with SD-WAN and ZTNA — learn how zero trust network access reshapes enterprise security beyond traditional site-to-site VPN.
solideinfo.com
September 25, 2026 at 11:27 AM
Comparing SSL/TLS and IPsec —  Choosing the Right Protocol for Your Network Needs
link.medium.com
December 8, 2024 at 4:47 PM
I can't tell you how phenomenally obscure this shit is. He had a hunch and kept passively insisting even as I tried to question how the IPsec Kerberos and ACL validation could occur/track without even AH encapsulation. Not something you're supposed to do so, it's essentially undocumented. Damn it.
June 22, 2026 at 9:15 PM
I am currently drinking a 100% Dark Chocolate made with Hotel Chocolat's velvetizer and a NIIIIIIIIIIIICE amount of Bailey's Irish Cream.

SUCK IT IPSEC
May 21, 2024 at 3:25 PM
Post-quantum Cloudflare IPsec will be on stage at Cisco Live next week! Sumant Mali will demo interconnecting Cisco 8000 Series Secure Routers via post-quantum Cloudflare IPsec tunnels. Check out these sessions to learn more: 𝗧𝗘𝗖𝗘𝗧𝗜-𝟮𝟰𝟬𝟭, 𝗧𝗘𝗖𝗔𝗥𝗖-𝟮𝟰𝟬𝟳, 𝗕𝗥𝗞𝗔𝗥𝗖-𝟮𝟴𝟴𝟱, 𝗖𝗧𝗙-𝟮𝟬𝟭𝟬. https://cfl.re/3RByVXt
May 28, 2026 at 1:47 PM
Tell me more? IPsec?
August 18, 2025 at 7:38 PM
Gave department presentation about my work using IPsec to lock-down peer communication between tens of thousands of our clients and the implementation package we're building for our ecosystem supplier partners so they can do the same thing with a validated framework.

What I work on these days...
August 3, 2026 at 11:01 PM
Verizon's VoLTE network is missing IPsec protection on SIP signaling, leaving users potentially exposed to call interception and spoofing. Verizon promised a fix, then said the requirements weren't actually mandatory, and went quiet.

Full story: https://bit.ly/4f2Op05
Verizon VoLTE network found missing IPsec protections for SIP signaling
Verizon's VoLTE infrastructure lacks IPsec integrity protection on the IMS network, which is required by industry specifications.
cyberinsider.com
July 11, 2026 at 11:06 PM