· via Cloudflare blog
Cloudflare and IETF add downgrade protection to shield IPsec from quantum attacks
Cloudflare worked with the IETF on an IPsec extension that blocks quantum downgrade attacks, and has enabled beta support in Cloudflare WAN and Magic Transit.

Cloudflare ships downgrade protection for IPsec
Cloudflare has worked with the IETF on an extension that hardens IPsec against quantum downgrade attacks, and beta support is already live in its network products. According to the Cloudflare blog, customers of Cloudflare WAN and Magic Transit can enable the feature by asking their account manager to turn on the ipsec_downgrade_protection flag for their account.
Why downgrade attacks threaten the post-quantum migration
As quantum computing advances, the industry is moving to post-quantum cryptography: algorithms believed to resist attack from quantum machines. Cloudflare explains that classical Diffie-Hellman key agreement must be replaced by post-quantum mechanisms such as ML-KEM, and classical signature schemes such as ECDSA and RSA by schemes such as ML-DSA.
The migration will, however, take years, and until it finishes, devices must keep supporting classical cryptography so they can connect with endpoints that have not been upgraded. That backwards compatibility creates an opening. In a downgrade attack, an attacker positioned between two endpoints manipulates the messages they exchange so that one side appears to have no post-quantum support at all. Both parties then settle on classical algorithms, which a quantum computer could break, so the protection post-quantum cryptography was meant to provide is silently discarded.
A design flaw in IKEv2
Cloudflare says it discovered — or rather rediscovered — a design flaw in IPsec that allows a more sophisticated attack, one that works regardless of which authentication method the connection uses.
Some protocol background helps. IPsec encrypts traffic at the IP layer, below where TLS and QUIC operate. Before encryption begins, the endpoints run an authenticated key agreement using IKEv2, typically across two phases. In the initial exchange, the initiator advertises the parameters it supports and sends a Diffie-Hellman key share; the responder chooses parameters and returns its own share. The endpoints then derive an encryption key, and in a following authentication exchange each side identifies itself and signs its key share and advertised parameters.
The weakness, according to Cloudflare, is that each party signs only its outbound messages rather than the entire handshake transcript, as TLS 1.3 does. Neither endpoint ever confirms that it observed the same sequence of messages as its peer. The resulting vulnerability allows a quantum attacker to decrypt all traffic between endpoints that both support post-quantum cryptography.
The attack is demanding: it requires a quantum computation to run in real time during the handshake, unlike harvest-now-decrypt-later scenarios where the quantum work happens entirely offline. Cloudflare says it cannot know whether or when such an attack becomes feasible, but resource estimates for quantum attacks on public-key cryptography have dropped dramatically — one reason the company moved its own transition deadline up to 2029.
The mitigation
To close the gap, Cloudflare helped the IETF develop an extension that adds a downgrade protection mechanism to IPsec. The protection is only effective when both parties support it, and Cloudflare hopes the rest of the IPsec ecosystem follows suit quickly.
The protocol matters to Cloudflare's business. Cloudflare IPsec lets organizations run IPsec connections across its global anycast network without costly MPLS links, while Magic Transit places that network in front of an organization's IP range to absorb threats such as DDoS attacks before handing scrubbed traffic back over IPsec tunnels.
Why it matters
Adding post-quantum algorithms to a protocol achieves little if an active attacker can strip them out mid-handshake; downgrade protection is what makes the migration meaningful. IPsec also sits unusually deep in the network stack, beneath TLS and QUIC, and underpins site-to-site links and enterprise connectivity across the internet, so a flaw affecting post-quantum-capable endpoints would undercut the entire transition. Because the fix requires both sides to implement it, adoption speed among vendors and network operators will determine how soon the protection holds in practice. Cloudflare points to encouraging signs: IPsec already supports post-quantum key agreement, and configurations that authenticate with pre-shared keys are already fully post-quantum today.
- #post-quantum-cryptography
- #ipsec
- #cloudflare
- #ietf
- #security