As quantum computing
technology advances, traditional encryption methods used in VPNs and
other secure communications become increasingly vulnerable to attacks.
In Advanced NGFW
to address
this emerging threat with quantum-resistant encryption methods to
protect your
overlay.
Post-Quantum pre-shared key (PQ PPK) is one of the key components of
post-quantum VPN that enhances the security of your IPSec tunnels by
adding an additional layer of quantum-resistant encryption. The
SD-WAN plugin allows you to enable post-quantum VPN
features for your VPN clusters and manage the associated settings.
When enabled, the plugin automatically generates and manages strong
PQ PPKs for your IPSec tunnels. The
SD-WAN plugin
configures IKE and IPSec Crypto profiles to use
quantum-safe algorithms
when post-quantum VPN is
enabled.
Select PQ PPK to enable PQ PPK for your SD-WAN overlay.
A warning appears:
Select OK to enable post-quantum VPN for the
VPN cluster. The SD-WAN plugin will automatically
generate 10 strong PQ PPKs to use with the IPSec tunnels. The SD-WAN plugin will configure the IPSec tunnels to use
PQ PPK with the negotiation mode set to preferred.
- PQ PPK isn’t supported on the PA-220 firewall.
- PQ PPK is supported only with Pre Shared
Key authentication type.
- When multiple VPN clusters with PQ PPK share a hub firewall,
then the shared hub firewall cannot simultaneously support
some clusters with PQ PPK enabled and others using standard
PSK authentication. That is, all VPN clusters connected to a
shared hub firewall must either use PSK or use PQ PPK.
- Existing VPN clusters won’t have post-quantum VPN configured
by default. This approach ensures there is no disruption to
existing IPSec connectivity. However, you have the
flexibility to manually enable post-quantum VPN for an
existing cluster if desired. When you do so, the IPSec
tunnels won’t be immediately affected. Instead, the
post-quantum capabilities will be negotiated when the keys
expire or when the tunnel is renegotiated. This gradual
adoption strategy enables you to implement quantum-safe
encryption at your own pace, balancing security enhancements
with operational stability.
If you want to refresh the PQ PPK list, use the Refresh
PQPPK List in the VPN cluster configuration. It
regenerates the new post-quantum pre-shared keys and updates the
keys on all SD-WAN devices within the selected VPN
cluster.
(HA deployments only) For Panorama in HA configuration, all
PQ PPK information is synchronized between the active and passive
peers, ensuring seamless failover. Similarly, for HA active/passive
firewalls, the PQ PPK list and all pre-shared keys, including
post-quantum key information, are synchronized between the devices.
This synchronization ensures that the PQ PPK configuration remains
consistent and operational across the HA pair, maintaining the
quantum-safe encryption capabilities of your SD-WAN
overlay even during failover events.