Features implemented For "old" IPsec, the algorithms are: For AH: null crypto checksum keyed MD5 with 128bit crypto checksum (see RFC1828) keyed SHA1 with 128bit crypto checksum HMAC MD5 with 128bit crypto checksum (see RFC2085) HMAC SHA1 with 128bit crypto checksum For ESP: null encryption (similar to RFC2410) DES-CBC mode (RFC1829) Can be useful to interoperate with some implementations