CLOUDFLARE reports a quantum-era threat to IPsec, where a sophisticated downgrade attack could allow a quantum-equipped attacker to decrypt traffic by forcing endpoints to abandon post-quantum (PQ) cryptography during the IKEv2 handshake. The attack exploits IPsec’s design where each party signs only its outgoing messages, not the entire handshake transcript, enabling identity misbinding or key compromise impersonation if an attacker can manipulate the initial exchanges.
While purely online quantum computation is required during the handshake to realise the breach, the risk is deemed non-negligible as quantum capabilities advance, underscoring the need to move beyond classical-only key exchange in IPsec.
To counter this, Cloudflare helped the IETF develop an extension for IKEv2 that introduces full transcript authentication (IKE_SA_INIT_FULL_TRANSCRIPT_AUTH). The approach requires both endpoints to support the extension and, crucially, to sign the entire handshake transcript rather than just outbound messages. Cloudflare has rolled out beta support in Cloudflare WAN and Magic Transit, enabling customers to opt in by asking their account managers to enable the ipsec_downgrade_protection flag on their accounts.
The extension relies on an unconditional notification mechanism: if either peer signals support for the extension, both sides adopt the updated, transcript-signing authentication logic; if both drop the notification, the old flow prevails, maintaining compatibility but leaving the downgrade risk. Cloudflare notes the extension is progressing towards RFC status, and advocates ecosystem-wide adoption as PQ migration continues.