---
title: "Cloudflare and IETF develop fix for IPsec quantum downgrade flaw"
description: "An authentication extension, now in beta in Cloudflare WAN and Magic Transit, stops tunnels falling back to classical encryption"
author: "rews desk"
published: 2026-09-29T13:00:00Z
modified: 2026-09-29T21:06:16Z
url: https://rews.cc/a/cloudflare-and-ietf-develop-fix-for-ipsec-quantum-downgrade--f61614
language: en
tags: ["quantum", "cybersecurity", "ipsec", "encryption", "post-quantum", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Cloudflare and IETF develop fix for IPsec quantum downgrade flaw

*An authentication extension, now in beta in Cloudflare WAN and Magic Transit, stops tunnels falling back to classical encryption*

By rews desk · September 29, 2026 · https://rews.cc/a/cloudflare-and-ietf-develop-fix-for-ipsec-quantum-downgrade--f61614

## In brief

- The flaw would let a quantum attacker decrypt all traffic between post-quantum-capable IPsec endpoints
- IKEv2 signs only each party’s outbound messages, not the full handshake transcript as TLS 1.3 does
- An attack would need a quantum computation in real time during the handshake; feasibility is unknown
- Beta support is available in Cloudflare WAN and Magic Transit via the ipsec\_downgrade\_protection flag
- Cloudflare has moved its full post-quantum transition deadline to 2029

Cloudflare said on Tuesday it had helped the Internet Engineering Task Force develop an extension that shields IPsec connections from quantum downgrade attacks, and had rolled out beta support across its own IPsec products.

The company said a design flaw in IPsec would allow an attacker with a quantum computer to decrypt all traffic between endpoints that support post-quantum encryption, regardless of which authentication method the endpoints use. The flaw matters because quantum computers are expected eventually to break classical cryptography such as Diffie-Hellman key agreement and RSA and ECDSA signatures, driving a migration to schemes such as ML-KEM and ML-DSA.

In a downgrade attack, an attacker positioned between a client and server manipulates their messages so each believes its peer lacks post-quantum support, forcing a return to classical encryption that a quantum computer can later break. Cloudflare said adding the new cryptographic primitives alone is not sufficient and that preventing attackers from downgrading connections is the next step in the migration.

The flaw lies in IKEv2, the protocol IPsec endpoints use to agree encryption keys: each party signs only its own outbound messages rather than the full handshake transcript, as the more recent TLS 1.3 protocol does, so neither endpoint confirms it observed the same sequence of messages as its peer.

Exploiting the flaw requires a quantum computation in real time during the handshake, which Cloudflare said makes it harder to carry out than a harvest-now, decrypt-later attack, in which the computation happens entirely offline. The company said it does not know if or when the attack will become feasible but cited caution, noting that resource estimates for quantum attacks on public key cryptography have decreased sharply; Cloudflare has [moved its full post-quantum transition deadline to 2029](https://blog.cloudflare.com/post-quantum-roadmap/).

The mitigation, an extension called IKE\_SA\_INIT\_FULL\_TRANSCRIPT\_AUTH developed with the IETF’s IPSECME working group and expected to be published as a formal standard according to [coverage of the effort](https://quantumzeitgeist.com/quantum-downgrade-attacks-cloudflare-shields/), adds authentication of the handshake transcript. Both parties must support the extension for it to work.

Cloudflare has enabled beta support in Cloudflare WAN and Magic Transit. Customers can activate it by asking their account managers to turn on the ipsec\_downgrade\_protection flag for their accounts, the company said.

IPsec encrypts traffic at the IP layer, below TLS and QUIC, and underpins several Cloudflare products. Cloudflare IPsec extends organizations’ connections over the company’s global network without multiprotocol label switching connections, and Magic Transit places Cloudflare’s network in front of an organization’s IP range to absorb attacks such as distributed denial-of-service floods before returning scrubbed traffic through IPsec tunnels.

The protocol has already been upgraded with post-quantum key agreement, and Cloudflare said it is on track to adopt post-quantum authentication on roughly the same timeline as TLS and QUIC, with pre-shared key authentication already fully post-quantum.

Cloudflare said it hopes the rest of the IPsec ecosystem adopts the extension, announced alongside the company’s Birthday Week program, “in short order.”
