Main features of Stormshield IPsec VPN Client 1.0
The Stormshield IPsec VPN client allows users to connect securely to the corporate network. It includes the following features.
Compatibility and interoperability of the Stormshield IPsec VPN client with
-
Operating systems: Windows 11, version 22H2 and higher. We recommend using Windows 11 Professional or Windows 11 Enterprise.
-
SNS firewalls: versions 4.8 LTSB and 5, either in standard IPsec or IPsec DR (Diffusion Restreinte).
IPsec/IKEv2 VPN
Standard IPsec profiles
The following algorithms and cryptographic functions are managed:
| Encryption | Key exchange (Diffie-Hellman) |
|
|
| Integrity | |
|
|
| PRF (Pseudo-Random Function) | |
|
ANSSI IPsec DR (Diffusion Restreinte) Profile
An IPsec DR (Diffusion Restreinte) profile is suggested when a VPN configuration is added. With this profile, a VPN can be configured in line with the ANSSI's IPsec DR guidelines (in French). The following cryptographic suites are suggested:
| Suite | Encryption | Integrity | Key exchange (Diffie-Hellman) | PRF |
|---|---|---|---|---|
| 1 | 256-bit AES GCM-16 | None* | Group 19 (256-bit ECP) | 256-bit SHA |
| 2 | 256-bit AES GCM-16 | None* | Group 28 (256-bit Brainpool ECP) | 256-bit SHA |
| 3 | 256-bit AES CTR | 256-bit SHA2 | Group 19 (256-bit ECP) | 256-bit SHA |
| 4 | 256-bit AES CTR | 256-bit SHA2 | Group 28 (256-bit Brainpool ECP) | 256-bit SHA |
(*) Integrity is natively guaranteed through the GCM encryption mode.
Multi-tunnel VPN configuration
The Stormshield IPsec VPN client makes it possible to add several VPN configurations. Do note that only one VPN tunnel can be set up at a time.
IKE fragmentation
IKEv2 packet fragmentation is enabled by default, with a maximum size of 1280 bytes. It is possible to change fragment size or disable fragmentation in a VPN's configuration (Fragmentation setting).
NAT-T (NAT-Traversal)
NAT-T is supported with a port that can be configured for IKE and encapsulated ESP (UDP/4500 by default). NAT-T lets the IPsec protocol pass through a network that performs dynamic address translation.
Config mode
In automatic mode (also known as “Config Mode” or "Configuration Payloads" in IKEv2, RFC 7296) makes it possible to retrieve the network configuration (IP address, mask, DNS servers) from the remote server. This network configuration can also be manually edited.
ESN negotiation
ESN negotiation (Extended Sequence Number, RFC 4304) can be enabled in a VPN's configuration (ESN setting). Doing so will enable the use of 64-bit anti-replay counters in IKEv2 and CHILD_SA. ESN negotiation has been designed to manage high throughput and long sessions.
Childless IKEv2
IKEv2 initiation without CHILD_SA (RFC 6023) can be enabled in a VPN's configuration (Childless mode setting). Enable this setting for advanced interoperability use cases.
Certificate authentication and management
Pre-shared key (PSK)
User authentication by pre-shared key is supported.
Certificate stored in the Windows certificate store
User authentication via X.509 v3 certificates stored in the Windows certificate store is supported.
Certificate revocation list verification mechanism (OCSP)
The OCSP-based certificate revocation and verification mechanism can be enabled in a VPN's configuration (Server Revocation Check setting).
VPN tunnel launch mode
Manual
The VPN tunnel has to be manually set up by the user after they have opened their Windows session. Automatic tunnel setup will be available in a future version of the Stormshield IPsec VPN client.
Deploying and configuring the VPN client
Local or managed installation
Stormshield IPsec VPN client can be installed and updated through an MSI package:
- Either locally on a workstation, by running the MSI package,
- Or using a method managed by an administrator, with a group policy (GPO, EMM or MDM) or in command line (CLI).
For more information, refer to the Stormshield IPsec VPN Client v1 Installation and User Guide.
Local or managed configuration
- Stormshield IPsec VPN client can be configured locally on a workstation by adding VPN configurations via the GUI.
- VPN configurations can be exported from or imported into the Stormshield IPsec VPN client. The supported format is JSON. Do note that VPN configuration secrets (PSK and certificates) are not exported.
-
A pool of Stormshield IPsec VPN clients can be configured in a managed manner with a group policy (GPO, EMM or MDM). Note that users will not be able to edit the settings that were retrieved from the server in their Stormshield IPsec VPN client.
Logs
Stormshield IPsec VPN client logs can be found in the Windows Event Viewer.
Advanced network features
Split tunneling mechanism
The split tunneling mechanism is supported. It makes it possible to determine which traffic has to pass through the VPN tunnel in order to reach remote networks that are defined by IP addresses or destination subnet masks.