In addition to configuring post-quantum IKEv2 VPNs based on RFC 8784, follow
RFC 6379 for
Suite B Cryptographic Suites for
IPsec
to upgrade your VPN connections to tough cipher suites, upgrade
your CA to 4K RSA key sizes to mitigate brute force attacks that can break smaller
key sizes and migrate your VPN certificate authentication to new certificates, and
upgrade to higher-bit SHA hash sizes such as SHA-384 and SHA-512.