Insecure Cipher Deprecation
Overview
As part of Cisco’s Resilient Infrastructure initiative, we are strengthening the security posture of IPsec VPN deployments by guiding customers toward modern cryptographic standards. This FAQ explains the impact to IPsec VPN features and configurations on MX security appliances in the Meraki Dashboard and what actions you need to take.
What is happening?
Aligned with the MX27.1 firmware release, we will remove support for legacy cryptographic algorithms used in ClientVPN (L2TP and IKEv2) and IPsec VPN (IKEv1 and IKEv2) configurations on MX security appliances.
These algorithms will no longer be configurable when creating new Non-Meraki VPN peers or when editing and saving changes to existing peers. Existing VPN peers currently using legacy algorithms will continue to function without interruption.
Client VPN proposals will not include legacy algorithms in their proposals.
The following legacy algorithms will be removed:
-
DES
-
3DES
-
MD5
-
Diffie-Hellman (DH) Group 1
-
Diffie-Hellman (DH) Group 2
-
Diffie-Hellman (DH) Group 5
-
Null encryption*
Customers currently using these legacy algorithms will need to migrate to modern algorithms for new VPN peers.
* "Null" encryption (no encryption) will continue to be supported only for the Zscaler preset for tunneling without encryption. New presets will be available that use modern algorithms.
When is this change happening?
Support for the listed legacy cryptographic algorithms is targeted for removal in the same timeframe as the MX 27.1 firmware release (early CY 2027). Legacy algorithms will no longer be configurable in the Dashboard or API when configuring new VPN peers or modifying existing peers. Customers are encouraged to begin transitioning to supported cryptographic standards as soon as possible.
What is the impact?
For IPSEC:
After the deprecation, the following behavior applies to all MX models regardless of current running firmware version:
-
New Non-Meraki VPN peers cannot be configured using legacy algorithms. Legacy algorithms will not appear as selectable options in the Dashboard or be configurable via API.
-
Existing VPN peers currently using legacy algorithms will continue to function without interruption.
-
If you edit and save changes to an existing peer that uses a legacy algorithm, you will not be able to re-select the legacy algorithm. You will be required to choose a supported modern algorithm before saving.
-
Deployments already using modern cryptographic standards are unaffected.
For Client VPN:
After upgrading to 27.1 the MX will no longer include insecure ciphers in their proposal. Please see Client VPN Overview for proposal details. Clients using Client VPN may need to update their proposals for connectivity. Please see Client VPN OS Configuration for configuration support.
What action do I need to take?
You should review and update your Client VPN and IPsec VPN configurations to use modern, secure cryptographic algorithms.
Recommended actions
-
Audit existing configurations
-
Identify any use of DES, 3DES, MD5, DH Group 1, DH Group 2, and DH Group 5
-
Update to modern algorithms, such as:
-
Encryption: AES-128, AES-192, AES-256
-
Integrity: SHA-1, SHA-256
-
Key Exchange: Diffie-Hellman Group 14 or higher (e.g., Group 14, 19, 20, 21)
-
Validate compatibility
-
Ensure both VPN peers support the updated algorithms
-
Test updated configurations
-
Verify tunnel establishment and traffic flow before production rollout
-
Plan upgrades proactively
-
Make changes ahead of the deprecation to avoid service interruptions
"Null" encryption (no encryption) will continue to be supported only for the Zscaler preset for tunneling without encryption.
How do I know if I am using legacy ciphers for IPSEC?
Follow the steps below to check your configuration in the Meraki Dashboard:
-
Log in to the Meraki Dashboard
-
Navigate to: Security & SD-WAN > Site-to-site VPN
-
Scroll to the Non-Meraki VPN peers section

-
Review each configured peer by clicking the three dots in the right column and selecting “Edit primary peer”

-
This will display the IPsec configuration for both Phase 1 and Phase 2. Review these settings to identify any legacy cryptographic algorithms. Please refer to the table below for legacy algorithms. For more information on configuring IPsec VPN peers please refer to the Site-to-Site VPN Settings article.
|
Phase |
Configuration |
Legacy Algorithms |
|---|---|---|
|
1 |
Encryption |
DES, 3DES |
|
1 |
Authentication |
MD5 |
|
1 |
Pseudo-random Function |
MD5 |
|
1 |
Diffie-Hellman Group (DH) |
1, 2, 5 |
|
2 |
Encryption |
DES, 3DES, Null* |
|
2 |
Authentication |
MD5 |
|
2 |
PFS Group |
1, 2, 5 |
Why is this change happening?
Legacy cryptographic algorithms no longer provide adequate protection against modern threats. Many of these algorithms are vulnerable to known cryptographic attacks or provide insufficient key strength, and therefore no longer meet current industry security standards.
By removing support for these outdated options, we aim to improve overall customer security posture, reduce exposure to cryptographic vulnerabilities, and align with industry best practices.
Who do I contact if I have additional questions?
If you need assistance or have questions:
-
Refer to Cisco documentation and support resources for IPsec VPN configuration guidance
-
Open a case with Support: https://meraki.cisco.com/meraki-support/overview/
-
Contact your Cisco account team

