FreeS/WAN VPN | Road Warrior | OE | ||||
PSK | RSA Secret | X.509 (requires patch) |
Manual Keying |
|||
More Compatible | ||||||
isakmpd (OpenBSD) | Yes | Yes | Yes | No | ||
Kame (FreeBSD, NetBSD) | Yes | Yes | Yes | No | ||
McAfee VPN was PGPNet |
Yes | Yes | Yes | Yes | No | |
Microsoft Windows 2000/XP |
Yes | Yes | with FreeS/WAN as Warrior |
No | ||
SSH Sentinel | Yes | Yes | Yes | No | ||
Safenet SoftPK /SoftRemote |
Yes | Yes | Yes | No | ||
Other | ||||||
6Wind | Yes | No | ||||
Alcatel Timestep | Yes | No | ||||
AshleyLaurent VPCom |
Yes | No | ||||
Borderware | Yes | No | No | |||
Check Point FW-1/VPN-1 | Yes | Yes | Yes | No | ||
Cisco with 3DES | Yes | Maybe | No | |||
F-Secure | Yes | No | ||||
Gauntlet GVPN | Yes | No | ||||
IBM AS/400 | Yes | No | ||||
Linksys | Maybe | No | Yes | No | ||
Lucent | Partial | No | ||||
Netasq | Yes | No | ||||
netcelo | Yes | No | ||||
Netscreen 5xp | Yes | Maybe | No | |||
Nortel Conitivity | Partial | No | ||||
RadGuard | Yes | No | ||||
Raptor | Yes | Yes | No | |||
Redcreek Ravlin | Yes/Partial | No | ||||
Shiva LANRover |
Yes | No | ||||
SonicWall | Yes | No | No | |||
Sun Solaris | Yes | No | ||||
Symantec | Yes | No | ||||
Watchguard Firebox |
Yes | Yes | No | |||
Xedia Access Point /QVPN |
Yes | No | ||||
PSK | RSA Secret | X.509 (requires patch) |
Manual Keying |
|||
FreeS/WAN VPN | Road Warrior | OE |
Our information comes primarily from mailing list reports and tutorials.
The FreeS/WAN project needs you! We rely on the user community to keep up to date. Mail users@lists.freeswan.org with your interop success stories.
Yes | People report that this works for them. |
[Blank] | We don't know. |
No | We have reason to believe it was, at some point, not possible to get this to work. |
Partial | Partial success. For example, a connection can be created from one end only. |
Yes/Partial | Mixed reports. |
Maybe | We think the answer is "yes", but need confirmation. |
OpenBSD FAQ: Using IPsec
Hans-Joerg Hoexer's interop Linux-OpenBSD (PSK)
Skyper's configuration (PSK)
French page with configs (X.509)
Kame homepage, with FAQ
NetBSD's IPSec FAQ
Itojun's Kame-FreeS/WAN interop tips (PSK)
Ghislaine Labouret's French page with links to matching FreeS/WAN and Kame configs (RSA)
Ghislaine's post explaining some peculiarities
Frodo's Kame-FreeS/WAN interop (X.509)
Using Kame as a WAVEsec client
Rekeying problem with FreeS/WAN and older PGPNets
DHCP over IPSEC HOWTO for FreeS/WAN (requires X.509 and dhcprelay patches)
Jean-Francois Nadeau's Net-net Configuration (PSK)
Telenor's Node-node Config (Transport-mode PSK)
Marcus Mueller's HOWTO using his VPN config tool (X.509). Tool also works with PSK.
Nate Carlson's HOWTO using same tool (Road Warrior with X.509). Unusually,
FreeS/WAN is the Road Warrior here.
Oscar Delgado's PDF (X.509, no configs)
Microsoft's page on Win2k TCP/IP security features
Microsoft's Win2k IPsec debugging tips
MS VPN may fall back to 1DES
SSH's Sentinel-FreeSWAN interop PDF (X.509)
Nadeem Hassan's
SUSE-to-Sentinel article (Road warrior with X.509)
Potential problem unless using Legacy Proposal option
Whit Blauvelt's SoftRemote tips
Tim Wilson's tips (X.509)
Jean-Francois Nadeau's
Practical Configuration (Road Warrior with PSK)
Terradon Communications' PDF (Road Warrior with PSK)
Seaan.net's PDF (Road Warrior to Subnet, with PSK)
Red Baron Consulting's PDF (Road Warrior with X.509)
French page with configs (X.509)
Alain Sabban's settings (PSK or PSK road warrior; through static NAT)
Derick Cassidy's configs (PSK)
David Kerry's Timestep settings (PSK)
Kevin Gerbracht's ipsec.conf (X.509)
Successful interop report, no details
Philip Reetz' configs (PSK)
Borderware server does not support FreeS/WAN road warriors
Older Borderware may not support Diffie Hellman groups 2, 5
French page with configs for Cisco IOS, PIX and VPN 3000 (X.509)
Text goes here.
Richard Reiner's ipsec.conf (PSK)
Might work without that pesky firewall... (PSK)
Richard Welty's tips and tricks
Ken Bantoft's instructions (Road Warrior with PSK)
Nate Carlson's caveats
Sample HOWTO through a Linksys Router
Nadeem Hasan's configs
Brock Nanson's tips
Partial success report; see also the next message in thread
French page with configs (X.509)
French page with configs (X.509)
Errol Neal's settings (PSK)
Corey Rogers' configs (PSK, no PFS)
Jordan Share's configs (PSK, 2 subnets, through static NAT)
Set src proxy_id to your protected subnet/mask
French page with ipsec.conf, Netscreen screen shots (X.509, may
need to revert to PSK...)
A report of a company using Netscreen with FreeS/WAN on a large scale (FreeS/WAN road warriors?)
French page with configs (X.509)
Marko Hausalo's configs (PSK). Note: These do create a connection,
as you can see by "IPsec SA established".
Claudia Schmeing's comments
John Hardy's configs (Manual)
Older Raptors want 3DES keys in 3 parts (Manual).
Different keys for each direction? (Manual)
Text goes here.
Wouter's config (PSK)
Dilan Arumainathan's configuration (PSK)
Dariush's setup... only opens
one way (PSK)
Text goes here.
Andreas Steffen's configs for Symantec 200R (PSK)
WatchGuard's HOWTO (PSK)
Ronald C. Riviera's Settings (PSK)
Max Enders' Configs (Manual)
Old known issue with auto keying
Tips on key generation and format (Manual)
Hybrid IPsec/L2TP connection settings (X.509)
Xedia's LAN-LAN links don't use multiple tunnels
That explanation, continued