Communications TLSv1.3 is the default for all communications. When the peer does not support TLSv1.3 then TLSv1.2 will be used as a fallback. The tunnel protocol used for the VPN connection can be configured in Sites > General. | Appliance to Appliance communication | nginx_peer_ciphers = TLS13-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384 Mutual certificate-based authentication with DN checking is used for communications between appliances (port 443) |
Client and Admin to Appliance communication (defaults) | nginx_client_ciphers = TLS13-AES256-GCM-SHA384:ECDHE-RSA-AES-256-GCM-SHA384 nginx client on 443 and 8443 | |
SSH to Appliance | Ciphers = AES-256-CTR, AES-192-CTR, AES-128-CTR | |
Client to Gateway tunnel | Cipher = TLS13-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384 Mutual certificate-based authentication with DN checking is used for communications | |
Single Packet Authorization | Cipher = AES-256-GCM | |
Appliance certificate generated by a Controller | SHA512 with RSA, keysize 4096 A Certificate Authority, Maximum number of intermediate CAs: 0, basicConstraints = critical, CA:true, pathlen:0, keyUsage = critical, digitalSignature, cRLSign, keyCertSign The CA cert is used for the controller-client authentication to communicate with appliances: extendedKeyUsage = clientAuth, serverAuth | |
Claim and entitlement token encryption | Cipher = AES-256-CTR | |
Database encryption | Cipher = AES-256-CTR | |
Backup file | Cipher = GPG symmetric (AES-256-CFB) | |
Cryptographic Module Validation Program (CMVP) FIPS | 6.4.1 and later desktop clients and appliances comply to FIPS 140-3 for to appliance-to-appliance and client-to-appliance communication using the wolfCrypt module. See the certificate. See FIPS 140-3: Security Requirements for Cryptographic Modules AppGate updates FIPS compliance as soon as there is a compliant cryptographic module available from wolfCrypt. 6.4.0 desktop clients and appliances comply to FIPS 140-2. | |
Common Criteria and NIAP Protection Profile (PP) | 6.4.2 clients were certified in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme for the Protection Profile for Application Software Version 1.4, with the Functional Package for Transport Layer Security (TLS) Version 1.1 applied. On May 19, 2026, the 7.0 appliance was filed for Common Criteria evaluation in accordance with the CCEVS process and scheme for the Protection Profile for Application Software Version 2.0, with Functional Package for Transport Layer Security Version 2.1 (TLS-PKG v2.1) and Functional Package for X.509 version 1.0 applied. | |
Security specifications
- Updated on Jul 16, 2026
- Published on Apr 3, 2026
- 1 minute read
Was this article helpful?