Technical reference
Enterprise VPN post-quantum compatibility matrix
A vendor-neutral view of post-quantum key establishment and authentication support across enterprise VPN platforms. Every record is scoped to an exact product and version range, carries its own sources and review date, and states key establishment and authentication separately.
16 records across 9 vendors
Dataset generated
Status model
What each status actually claims
The distance between “the vendor documents it” and “PQVPN watched it negotiate” is the most important distinction in this table, so the two never share a label or a colour.
- Verified supportedVerified supported
- PQVPN has observed this mechanism negotiate on this product and release. Configuration support alone is not enough for this status.
- Documented supportedDocumented supported
- The vendor documents support for this product and release. PQVPN has read the documentation but has not independently observed a negotiation.
- PartialPartial
- Support exists but is constrained — by mode, by licence, by platform variant, or by which peer initiates.
- ExperimentalExperimental
- Present but labelled by the vendor as preview, beta, or not for production use.
- RoadmapRoadmap
- Announced or committed by the vendor, not available in a shipping release.
- Requires exact-version reviewRequires exact-version review
- Support genuinely differs across releases within this product family. The exact release must be checked before any migration decision.
- UnsupportedUnsupported
- Documented as not available on this product and release.
- UnknownUnknown
- PQVPN has not established a position. Treat as an open question, not as a no.
The matrix
Filter the compatibility records
Showing 16 of 16 records. No filters applied.
| Vendor | Product | Key establishment |
|---|---|---|
| AWS VPN | AWS Site-to-Site VPN (Virtual Private Gateway and Transit Gateway attachments) | Post-quantum key establishment: Unknown |
| Azure VPN Gateway | Azure VPN Gateway site-to-site connections | Post-quantum key establishment: Unknown |
| Check Point | Check Point Quantum Security Gateway on Gaia | Post-quantum key establishment: Unsupported |
| Check Point | Check Point Quantum Security Gateway on Gaia | Post-quantum key establishment: Requires exact-version review |
| Cisco | Cisco ASA 5500-X and Secure Firewall in ASA mode | Post-quantum key establishment: Requires exact-version review |
| Cisco | Cisco IOS XE routers (Catalyst 8000, ISR 4000, ASR 1000) | Post-quantum key establishment: Requires exact-version review |
| Cisco | Cisco Meraki MX security appliances | Post-quantum key establishment: Unknown |
| Fortinet | FortiGate appliances and VMs running FortiOS | Post-quantum key establishment: Unsupported |
| Fortinet | FortiGate appliances and VMs running FortiOS | Post-quantum key establishment: Requires exact-version review |
| Google Cloud VPN | Google Cloud Classic VPN | Post-quantum key establishment: Unsupported |
| Google Cloud VPN | Google Cloud HA VPN | Post-quantum key establishment: Unsupported |
| Palo Alto Networks | PA-Series and VM-Series running PAN-OS | Post-quantum key establishment: Unsupported |
| Palo Alto Networks | PA-Series, VM-Series and CN-Series running PAN-OS | Post-quantum key establishment: Requires exact-version review |
| strongSwan | strongSwan IKEv2 daemon | Post-quantum key establishment: Unsupported |
| strongSwan | strongSwan IKEv2 daemon | Post-quantum key establishment: Requires exact-version review |
| WireGuard | WireGuard protocol (in-kernel and userspace implementations) | Post-quantum key establishment: Unsupported |
Record detail
By vendor
Vendor pages
Each vendor page explains what that vendor's position actually depends on in an estate — release trains, licence gating, management topology, peer constraints — and what to establish before a migration wave is planned.
- CiscoCisco IOS and IOS XE routers, Catalyst platforms, ASA and Secure Firewall (FTD) appliances, and Meraki MX security appliances terminating site-to-site IPsec.
- FortinetFortiGate appliances and virtual machines running FortiOS and terminating site-to-site IPsec, managed standalone or through FortiManager.
- Palo Alto NetworksPA-Series appliances, VM-Series virtual firewalls and CN-Series running PAN-OS and terminating site-to-site IPsec, managed standalone or through Panorama.
- Check PointCheck Point Quantum Security Gateways running Gaia, managed through Security Management or Multi-Domain Security Management, terminating site-to-site IPsec.
- strongSwanstrongSwan IKEv2 daemons on Linux and BSD, configured through swanctl or the legacy ipsec.conf interface, used as a software VPN gateway or as an overlay terminator.
- AWS VPNAWS Site-to-Site VPN, including Virtual Private Gateway and Transit Gateway attachments, and the tunnel options exposed through the VPN connection API.
- Azure VPN GatewayAzure VPN Gateway site-to-site connections, including custom IPsec/IKE policy on connection objects, across the supported gateway SKUs.
- Google Cloud VPNGoogle Cloud HA VPN and Classic VPN tunnels, and the IKE cipher set the service supports for site-to-site connections.
- WireGuardThe WireGuard protocol and its in-kernel and userspace implementations, used for site-to-site and infrastructure tunnels.
Need this mapped to your actual estate?
This table narrows the research. An assessment answers it for your exact devices, your exact releases and your actual peers — including the ones that belong to somebody else.