Cloudflare IPsec Adds Post-Quantum Hybrid ML-KEM Encryption
Patch IPsec deployments to use hybrid ML‑KEM (FIPS 203) and test with Fortinet 7.6.6 or Cisco 8000 26.1.1 for interoperability.
Patch IPsec configurations to enable hybrid ML‑KEM (FIPS 203) and verify connectivity with Fortinet 7.6.6 and Cisco 8000 26.1.1.
Summary
Cloudflare has made post‑quantum encryption in its IPsec product generally available, moving its target for full post‑quantum security to 2029 in response to recent quantum‑computing advances. The new implementation uses the hybrid ML‑KEM (FIPS 203) draft‑ietf‑ipsecme‑ikev2‑mlkem, combining a classical Diffie‑Hellman exchange with ML‑KEM to stop harvest‑now‑decrypt‑later attacks. Interoperability tests have confirmed that Fortinet FortiOS 7.6.6+ and Cisco 8000 Series Secure Routers 26.1.1+ can now establish post‑quantum Cloudflare IPsec tunnels using the same draft. Cloudflare IPsec’s hybrid handshake runs first with Diffie‑Hellman, then encrypts a second ML‑KEM exchange, and mixes both outputs into the session keys for ESP traffic. The draft was published in late 2025, roughly four years after its TLS counterpart landed, and the implementation was previously in closed beta.
This release means that customers can protect their WAN against quantum‑era attacks today using existing hardware, without waiting for new cryptographic standards or specialized equipment. The move also aligns with Cloudflare’s broader post‑quantum roadmap, which now includes a 2029 target for full network‑wide post‑quantum security.
The announcement also highlights the importance of interoperable standards, noting that earlier RFC 9370 implementations suffered from ciphersuite bloat and limited interoperability, whereas the new draft resolves these gaps.
Key changes
- Cloudflare IPsec now supports hybrid ML‑KEM (FIPS 203) to stop harvest‑now‑decrypt‑later attacks
- Interoperability confirmed with Fortinet FortiOS 7.6.6+ and Cisco 8000 Series Secure Routers 26.1.1+
- Hybrid handshake uses Diffie‑Hellman followed by ML‑KEM and mixes outputs into session keys
- Draft‑ietf‑ipsecme‑ikev2‑mlkem released in late 2025 and now generally available
- Cloudflare moved target for full post‑quantum security to 2029
- Closed beta of the implementation was previously available
- Post‑quantum encryption stops harvest‑now‑decrypt‑later attacks
- Cloudflare IPsec now generally available