AES-256
A symmetric encryption cipher with a 256-bit key, standard in OpenVPN and IKEv2 configurations.
Glossary
Generating a new session key for each connection, so a future key compromise cannot decrypt past recorded traffic.
It defends against the realistic attack: record encrypted traffic now, obtain the key later. Without it, one key compromise retroactively exposes everything captured.
It is standard in modern configurations rather than a differentiator, and both WireGuard and correctly configured OpenVPN provide it. Its absence would be a serious finding; its presence is not a selling point.
A symmetric encryption cipher with a 256-bit key, standard in OpenVPN and IKEv2 configurations.
The set of rules governing how the tunnel is established and how data is encrypted inside it.
Terms are defined here because they appear in our scoring rubric or in provider reviews, not to fill a glossary.