HTTP/1.1 302 Found
Date: Fri, 10 Oct 2025 17:50:06 GMT
Server: Apache
X-Content-Type-Options: nosniff
Vary: Accept-Encoding
Location: https://www.iana.org/assignments/ikev2-parameters
Content-Length: 0
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Cache-Control: public, s-maxage=1800, max-age=3600
Expires: Fri, 10 Oct 2025 18:50:06 GMT
Content-Type: text/html; charset=utf-8
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Strict-Transport-Security: max-age=48211200; preload
HTTP/1.1 302 Found
Date: Fri, 10 Oct 2025 17:50:06 GMT
Server: Apache
X-Content-Type-Options: nosniff
Vary: Accept-Encoding
Location: https://www.iana.org/assignments/ikev2-parameters/ikev2-parameters.xhtml
Content-Length: 0
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Cache-Control: public, s-maxage=1800, max-age=3600
Expires: Fri, 10 Oct 2025 18:50:06 GMT
Content-Type: text/html; charset=utf-8
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Strict-Transport-Security: max-age=48211200; preload
HTTP/1.1 200 OK
Date: Fri, 10 Oct 2025 17:50:06 GMT
Server: Apache
X-Content-Type-Options: nosniff
Vary: Accept-Encoding
Last-Modified: Fri, 23 May 2025 20:55:15 GMT
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Cache-Control: public, s-maxage=1800, max-age=3600
Expires: Fri, 10 Oct 2025 18:50:06 GMT
Content-Type: text/html; charset=UTF-8
Content-Encoding: gzip
Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;
Transfer-Encoding: chunked
Strict-Transport-Security: max-age=48211200; preload
Internet Key Exchange Version 2 (IKEv2) Parameters
Internet Key Exchange Version 2 (IKEv2) Parameters
Created
2005-01-18
Last Updated
2025-05-23
Available Formats
XML
HTML
Plain text
Registries Included Below
IKEv2 Exchange Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
IKEv2 Payload Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
Transform Type Values
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ][RFC9370 ]
Note
"Key Exchange Method (KE)" transform type was originally
named "Diffie-Hellman Group (D-H)" and was referenced by
that name in a number of RFCs published prior
to [RFC9370 ], which gave it the current title.
Note
All "Additional Key Exchange (ADDKE)" entries use the same
"Transform Type 4 - Key Exchange Method Transform IDs"
registry as the "Key Exchange Method (KE)" entry.
Note
"Sequence Numbers (SN)" transform type was originally named
"Extended Sequence Numbers (ESN)" and was referenced by
that name in a number of RFCs published prior to
[RFC-ietf-ipsecme-ikev2-rename-esn-04 ], which gave it the
current title.
Available Formats
CSV
Type
Description
Used In
Reference
0
Reserved
[RFC7296 ]
1
Encryption Algorithm (ENCR)
(IKE, GIKE_UPDATE, ESP)
[RFC7296 ][RFC-ietf-ipsecme-g-ikev2-21 ]
2
Pseudo-random Function (PRF)
(IKE)
[RFC7296 ]
3
Integrity Algorithm (INTEG)
(IKE, GIKE_UPDATE, AH, optional in ESP)
[RFC7296 ][RFC-ietf-ipsecme-g-ikev2-21 ]
4
Key Exchange Method (KE)
(IKE, optional in AH, ESP)
[RFC7296 ][RFC9370 ]
5
Sequence Numbers (SN)
(AH, ESP)
[RFC7296 ][RFC-ietf-ipsecme-ikev2-rename-esn-04 ]
6
Additional Key Exchange 1 (ADDKE1)
(optional in IKE, AH, ESP)
[RFC9370 ]
7
Additional Key Exchange 2 (ADDKE2)
(optional in IKE, AH, ESP)
[RFC9370 ]
8
Additional Key Exchange 3 (ADDKE3)
(optional in IKE, AH, ESP)
[RFC9370 ]
9
Additional Key Exchange 4 (ADDKE4)
(optional in IKE, AH, ESP)
[RFC9370 ]
10
Additional Key Exchange 5 (ADDKE5)
(optional in IKE, AH, ESP)
[RFC9370 ]
11
Additional Key Exchange 6 (ADDKE6)
(optional in IKE, AH, ESP)
[RFC9370 ]
12
Additional Key Exchange 7 (ADDKE7)
(optional in IKE, AH, ESP)
[RFC9370 ]
13
Key Wrap Algorithm (KWA)
(IKE, GIKE_UPDATE)
[RFC-ietf-ipsecme-g-ikev2-21 ]
14
Group Controller Authentication Method (GCAUTH)
(GIKE_UPDATE)
[RFC-ietf-ipsecme-g-ikev2-21 ]
15-240
Unassigned
241-255
Reserved for Private Use
[RFC7296 ]
IKEv2 Transform Attribute Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
Transform Type 1 - Encryption Algorithm Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ][RFC9395 ]
Note
To find out requirement levels for encryption algorithms for
ESP, see [RFC8221 ]. For IKEv2, see [RFC8247 ].
Available Formats
CSV
Transform Type 2 - Pseudorandom Function Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ][RFC9395 ]
Note
To find out requirement levels for PRFs for IKEv2, see [RFC8247 ].
Available Formats
CSV
Transform Type 3 - Integrity Algorithm Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ][RFC9395 ]
Note
To find out requirement levels for encryption algorithms for
ESP/AH, see [RFC8221 ]. For IKEv2, see [RFC8247 ].
Available Formats
CSV
Transform Type 4 - Key Exchange Method Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ][RFC6989 ][RFC9370 ][RFC9395 ]
Note
This registry was originally named "Transform Type 4 -
Diffie-Hellman Group Transform IDs" and was referenced
using that name in a number of RFCs published prior to
[RFC9370 ], which gave it its current title.
Note
This registry is used by the "Key Exchange Method (KE)"
transform type and by all "Additional Key Exchange (ADDKE)"
transform types.
Note
To find out requirement levels for key exchange methods
for IKEv2, see [RFC8247 ].
Note
The instructions for the designated experts are described
in [RFC9370 ]. While adding new Key Exchange (KE) methods,
the following considerations must be applied. A key
exchange method must take exactly one round trip (one IKEv2
exchange) and at the end of this exchange, both peers must
be able to derive the shared secret. In addition, any
public value that peersexchanged during a key exchange
method must fit into asingle IKEv2 payload. If these
restrictions are not metfor a key exchange method, then
there must be documentationon how this key exchange method
is used in IKEv2.
Available Formats
CSV
Number
Name
Status
Recipient Tests
Reference
0
NONE
[RFC7296 ]
1
768-bit MODP Group
DEPRECATED [RFC8247 ]
[RFC6989 ], Sec. 2.1
[RFC7296 ]
2
1024-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC7296 ]
3-4
Reserved
[RFC7296 ]
5
1536-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC3526 ]
6-13
Unassigned
[RFC7296 ]
14
2048-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC3526 ]
15
3072-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC3526 ]
16
4096-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC3526 ]
17
6144-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC3526 ]
18
8192-bit MODP Group
[RFC6989 ], Sec. 2.1
[RFC3526 ]
19
256-bit random ECP group
[RFC6989 ], Sec. 2.3
[RFC5903 ]
20
384-bit random ECP group
[RFC6989 ], Sec. 2.3
[RFC5903 ]
21
521-bit random ECP group
[RFC6989 ], Sec. 2.3
[RFC5903 ]
22
1024-bit MODP Group with 160-bit Prime Order Subgroup
DEPRECATED [RFC8247 ]
[RFC6989 ], Sec. 2.2
[RFC5114 ]
23
2048-bit MODP Group with 224-bit Prime Order Subgroup
[RFC6989 ], Sec. 2.2
[RFC5114 ]
24
2048-bit MODP Group with 256-bit Prime Order Subgroup
[RFC6989 ], Sec. 2.2
[RFC5114 ]
25
192-bit Random ECP Group
[RFC6989 ], Sec. 2.3
[RFC5114 ]
26
224-bit Random ECP Group
[RFC6989 ], Sec. 2.3
[RFC5114 ]
27
brainpoolP224r1
[RFC6989 ], Sec. 2.3
[RFC6954 ]
28
brainpoolP256r1
[RFC6989 ], Sec. 2.3
[RFC6954 ]
29
brainpoolP384r1
[RFC6989 ], Sec. 2.3
[RFC6954 ]
30
brainpoolP512r1
[RFC6989 ], Sec. 2.3
[RFC6954 ]
31
Curve25519
[RFC8031 ], Sec. 3.2
[RFC8031 ]
32
Curve448
[RFC8031 ], Sec. 3.2
[RFC8031 ]
33
GOST3410_2012_256
[RFC9385, Sec. 6.1 ]
[RFC9385 ]
34
GOST3410_2012_512
[RFC9385, Sec. 6.1 ]
[RFC9385 ]
35
ml-kem-512
[draft-kampanakis-ml-kem-ikev2-08, Sec. 2.3 ]
[draft-kampanakis-ml-kem-ikev2-08 ]
36
ml-kem-768
[draft-kampanakis-ml-kem-ikev2-08, Sec. 2.3 ]
[draft-kampanakis-ml-kem-ikev2-08 ]
37
ml-kem-1024
[draft-kampanakis-ml-kem-ikev2-08, Sec. 2.3 ]
[draft-kampanakis-ml-kem-ikev2-08 ]
38-1023
Unassigned
1024-65535
Reserved for Private Use
[RFC7296 ]
Transform Type 5 - Sequence Numbers Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ][RFC-ietf-ipsecme-ikev2-rename-esn-04 ]
Note
This registry was originally named "Transform Type 5 -
Extended Sequence Numbers Transform IDs" and was referenced
using that name in a number of RFCs published prior to
[RFC-ietf-ipsecme-ikev2-rename-esn-04 ], which gave it the
current title.
Note
"32-bit Sequential Numbers" transform ID was originally
named "No Extended Sequence Numbers" and was referenced by
that name in a number of RFCs published prior to
[RFC-ietf-ipsecme-ikev2-rename-esn-04 ], which gave it the
current title.
Note
"Partially Transmitted 64-bit Sequential Numbers" transform
ID was originally named "Extended Sequence Numbers" and was
referenced by that name in a number of RFCs published prior
to [RFC-ietf-ipsecme-ikev2-rename-esn-04 ], which gave it
the current title.
Note
Numbers in the range 2-65535 were originally marked as
"Reserved" referencing [RFC7296 ], and were re-classified
as "Unassigned" and "Private Use" by [RFC-ietf-ipsecme-ikev2-rename-esn-04 ].
Available Formats
CSV
Transform Type 13 - Key Wrap Algorithm Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Unassigned
Reference
[RFC-ietf-ipsecme-g-ikev2-21 ]
Available Formats
CSV
Transform Type 14 - Group Controller Authentication Method Transform IDs
Registration Procedure(s)
Expert Review
Expert(s)
Unassigned
Reference
[RFC-ietf-ipsecme-g-ikev2-21 ]
Available Formats
CSV
IKEv2 Identification Payload ID Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen
Reference
[RFC7296 ]
Available Formats
CSV
IKEv2 Certificate Encodings
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
Value
Certificate Encoding
Reference
0
Reserved
[RFC7296 ]
1
PKCS #7 wrapped X.509 certificate
[UNSPECIFIED]
2
PGP Certificate
[UNSPECIFIED]
3
DNS Signed Key
[UNSPECIFIED]
4
X.509 Certificate - Signature
[RFC7296 ]
5
Reserved
[RFC7296 ]
6
Kerberos Token
[UNSPECIFIED]
7
Certificate Revocation List (CRL)
[RFC7296 ]
8
Authority Revocation List (ARL)
[UNSPECIFIED]
9
SPKI Certificate
[UNSPECIFIED]
10
X.509 Certificate - Attribute
[UNSPECIFIED]
11
Raw RSA Key (DEPRECATED)
[RFC7296 ]
12
Hash and URL of X.509 certificate
[RFC7296 ]
13
Hash and URL of X.509 bundle
[RFC7296 ]
14
OCSP Content
[RFC4806 ]
15
Raw Public Key
[RFC7670 ]
16-200
Unassigned
201-255
Reserved for Private Use
[RFC7296 ]
IKEv2 Authentication Method
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Note
To find out requirement levels for IKEv2 authentication
methods, see [RFC8247 ].
Available Formats
CSV
Value
Authentication Method
Reference
0
Reserved
[RFC7296 ]
1
RSA Digital Signature
[RFC7296 ]
2
Shared Key Message Integrity Code
[RFC7296 ]
3
DSS Digital Signature
[RFC7296 ]
4-8
Unassigned
[RFC7296 ]
9
ECDSA with SHA-256 on the P-256 curve
[RFC4754 ]
10
ECDSA with SHA-384 on the P-384 curve
[RFC4754 ]
11
ECDSA with SHA-512 on the P-521 curve
[RFC4754 ]
12
Generic Secure Password Authentication Method
[RFC6467 ]
13
NULL Authentication
[RFC7619 ]
14
Digital Signature
[RFC7427 ]
15-200
Unassigned
201-255
Reserved for Private Use
[RFC7296 ]
IKEv2 Notify Message Error Types
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
Range
Registration Procedures
0-8191
Expert Review
8192-16383
Private Use
IKEv2 Notify Message Status Types
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
Range
Registration Procedures
16384-40959
Expert Review
40960-65535
Private Use
IKEv2 Notification IPCOMP Transform IDs (Value 16387)
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Note
To find out requirement levels for IPCOMP methods, see [RFC8221 ].
Available Formats
CSV
Value
Compression Type
Reference
0
Reserved
[RFC7296 ]
1
IPCOMP_OUI
[UNSPECIFIED]
2
IPCOMP_DEFLATE
[RFC2394 ]
3
IPCOMP_LZS
[RFC2395 ]
4
IPCOMP_LZJH
[RFC3051 ]
5-240
Unassigned
241-255
Reserved for Private Use
[RFC7296 ]
IKEv2 Security Protocol Identifiers
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
IKEv2 Traffic Selector Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
Value
TS Type
Reference
0-6
Reserved
[RFC7296 ]
7
TS_IPV4_ADDR_RANGE
[RFC7296 ]
8
TS_IPV6_ADDR_RANGE
[RFC7296 ]
9
TS_FC_ADDR_RANGE
[RFC4595 ]
10
TS_SECLABEL
[RFC9478 ]
11-240
Unassigned
241-255
Reserved for Private Use
[RFC7296 ]
IKEv2 Configuration Payload CFG Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Available Formats
CSV
IKEv2 Configuration Payload Attribute Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7296 ]
Note
Attribute Types with an "*" may be multi-valued on return only if
multiple values were requested.
Available Formats
CSV
IKEv2 Gateway Identity Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC5685 ]
Available Formats
CSV
Value
Description
Reference
0
Reserved
[RFC5685 ]
1
IPv4 address of the VPN gateway
[RFC5685 ]
2
IPv6 address of the VPN gateway
[RFC5685 ]
3
FQDN of the VPN gateway
[RFC5685 ]
4-240
Unassigned
241-255
Reserved for Private Use
[RFC5685 ]
ROHC Attribute Types
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC5857 ]
Available Formats
CSV
Value
ROHC Attribute Type
Format
Reference
0
Reserved
[RFC5857 ]
1
Maximum Context Identifier (MAX_CID)
TV
[RFC5857 ]
2
ROHC Profile (ROHC_PROFILE)
TV
[RFC5857 ]
3
ROHC Integrity Algorithm (ROHC_INTEG)
TV
[RFC5857 ]
4
ROHC ICV Length in bytes (ROHC_ICV_LEN)
TV
[RFC5857 ]
5
Maximum Reconstructed Reception Unit (MRRU)
TV
[RFC5857 ]
6-16383
Unassigned
16384-32767
Reserved for Private Use
[RFC5857 ]
IKEv2 Secure Password Methods
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC6467 ]
Available Formats
CSV
Value
Description
Reference
0
Reserved
[RFC6467 ]
1
PACE
[RFC6631 ]
2
AugPAKE
[RFC6628 ]
3
Secure PSK Authentication
[RFC6617 ]
4-1023
Unassigned
1024-65535
Reserved for Private Use
[RFC6467 ]
IKEv2 Hash Algorithms
Registration Procedure(s)
Expert Review
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC7427 ]
Note
To find out requirement levels for IKEv2 hash algorithms, see
[RFC8247 ].
Available Formats
CSV
IKEv2 Post-quantum Preshared Key ID Types
Expert(s)
Tero Kivinen, Valery Smyslov
Reference
[RFC8784 ]
Available Formats
CSV
Range
Registration Procedures
1-127
Expert Review
128-255
Private Use
Value
PPK_ID Type
Reference
0
Reserved
[RFC8784 ]
1
PPK_ID_OPAQUE
[RFC8784 ]
2
PPK_ID_FIXED
[RFC8784 ]
3-127
Unassigned
128-255
Reserved for Private Use
[RFC8784 ]
GSA Attributes
Registration Procedure(s)
Expert Review
Expert(s)
Unassigned
Reference
[RFC-ietf-ipsecme-g-ikev2-21 ]
Available Formats
CSV
Group-wide Policy Attributes
Registration Procedure(s)
Expert Review
Expert(s)
Unassigned
Reference
[RFC-ietf-ipsecme-g-ikev2-21 ]
Available Formats
CSV
Group Key Bag Attributes
Registration Procedure(s)
Expert Review
Expert(s)
Unassigned
Reference
[RFC-ietf-ipsecme-g-ikev2-21 ]
Available Formats
CSV
Member Key Bag Attributes
Registration Procedure(s)
Expert Review
Expert(s)
Unassigned
Reference
[RFC-ietf-ipsecme-g-ikev2-21 ]
Available Formats
CSV
Contact Information