Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

2 Replies

  • I can confirm that it's possible to create an IPSEC tunnel between a F5-BIG-IP and a Check Point firewall. I've been testing this in my lab with R80.10 and it's working. I've noticed that it is key to use PFS in Phase 2. Without PFS in Phase 2 it didn't work. Here are some settings I tried:

    Phase 1:

    SHA-1/AES-128 + DH Group 2 works!
    SHA-256/AES-256 + DH Group 2 works!
    

    Phase 2:

    SHA-1/3DES + MODP1024 works!
    SHA-1/AES-128 + MODP1024 works!
    SHA-1/AES-256 + MODP1024 works! 
    SHA-256/AES-256 + MODP1024 works!