Today's VPNs use Diffie-Hellman key exchange, which a sufficiently large quantum computer could break. The worry is 'harvest now, decrypt later': an attacker records encrypted VPN traffic today and decrypts it years from now once the key exchange can be broken. For data that must stay confidential for a long time, that future risk is a present problem. Quantum-resistant VPN features in recent PAN-OS releases address this for IKEv2 (Internet Key Exchange version 2) site-to-site tunnels. This lesson also covers GRE, a simple tunnel with no cryptography at all, so you can tell the two apart.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.