Contents Previous Next

Interoperating with FreeS/WAN

* PLEASE NOTE * This document is in process. If a section you are looking for is not yet complete, you can use our old interop document.

Interop at a Glance

 FreeS/WAN VPNRoad Warrior OE
 PSKRSA SecretX.509
(requires patch)
Manual
Keying
  
More Compatible
isakmpd (OpenBSD)   Yes  YesYes No    
Kame (FreeBSD, NetBSD)   Yes  YesYes No
McAfee VPN
was PGPNet
 
YesYes Yes  YesNo
Microsoft
Windows 2000/XP
 
Yes Yes  with FreeS/WAN
as Warrior
No
SSH Sentinel   Yes  Yes YesNo
Safenet SoftPK
/SoftRemote
 
Yes Yes  YesNo
Other
6Wind     Yes  No
Alcatel Timestep   Yes     No
AshleyLaurent
VPCom
 
Yes     No
Borderware   Yes    NoNo
Check Point FW-1/VPN-1  Yes  Yes YesNo
Cisco with 3DES   YesMaybe    No
F-Secure   Yes     No
Gauntlet GVPN   Yes     No
IBM AS/400   Yes     No
Intel Shiva
LANRover/Net Structure
 
Yes     No
Linksys   Maybe  No YesNo
Lucent  Partial     No
Netasq     Yes   No
netcelo     Yes   No
Netscreen 5xp   Yes    MaybeNo
Nortel Contivity   Partial  Yes  No
RadGuard   Yes     No
Raptor  Yes   Yes No
Redcreek Ravlin   Yes/Partial      No
SonicWall   Yes   NoNo
Sun Solaris      Yes No
Symantec   Yes     No
Watchguard
Firebox
 
Yes  Yes  No
Xedia Access Point
/QVPN
 
Yes     No
 PSKRSA SecretX.509
(requires patch)
Manual
Keying
  
 FreeS/WAN VPNRoad Warrior OE

Our information comes primarily from mailing list reports and tutorials.

The FreeS/WAN project needs you! We rely on the user community to keep up to date. Mail users@lists.freeswan.org with your interop success stories.

Key

YesPeople report that this works for them.
[Blank]We don't know.
NoWe have reason to believe it was, at some point, not possible to get this to work.
PartialPartial success. For example, a connection can be created from one end only.
Yes/Partial Mixed reports.
MaybeWe think the answer is "yes", but need confirmation.

Basic Interop Rules

You want to choose X, Y, Z.

Longer Stories

For More Compatible Implementations

isakmpd (OpenBSD)

OpenBSD FAQ: Using IPsec
Hans-Joerg Hoexer's interop Linux-OpenBSD (PSK)
Skyper's configuration (PSK)
French page with configs (X.509)

Back to chart

Kame for FreeBSD, NetBSD

Kame homepage, with FAQ
NetBSD's IPSec FAQ

Itojun's Kame-FreeS/WAN interop tips (PSK)
Ghislaine Labouret's French page with links to matching FreeS/WAN and Kame configs (RSA)
     Ghislaine's post explaining some peculiarities
Frodo's Kame-FreeS/WAN interop (X.509)
Using Kame as a WAVEsec client

Back to chart

PGPNet/McAfee

Hans-Joerg Hoexer's Guide for Linux-PGPNet (PSK)
Kai Martius' instructions using RSA Key-Extractor Tool (RSA)
    Christian Zeng's page (RSA) based on Kai's work. English or German.
Oscar Delgado's PDF (X.509, no configs)
Ryan's HOWTO for FreeS/WAN-PGPNet (X.509). Through a Linksys Router with IPsec Passthru enabled.
Jean-Francois Nadeau's Practical Configuration (Road Warrior with PSK)
Wouter Prins' HOWTO (Road Warrior with X.509)

Rekeying problem with FreeS/WAN and older PGPNets

DHCP over IPSEC HOWTO for FreeS/WAN (requires X.509 and dhcprelay patches)

Back to chart

Microsoft Windows 2000/XP

Jean-Francois Nadeau's Net-net Configuration (PSK)
Telenor's Node-node Config (Transport-mode PSK)
Marcus Mueller's HOWTO using his VPN config tool (X.509). Tool also works with PSK.
Nate Carlson's HOWTO using same tool (Road Warrior with X.509). Unusually, FreeS/WAN is the Road Warrior here.
Oscar Delgado's PDF (X.509, no configs)

Microsoft's page on Win2k TCP/IP security features
Microsoft's Win2k IPsec debugging tips
MS VPN may fall back to 1DES

Back to chart

SSH Sentinel

SSH's Sentinel-FreeSWAN interop PDF (X.509)
Nadeem Hassan's SUSE-to-Sentinel article (Road warrior with X.509)
Potential problem unless using Legacy Proposal option

Back to chart

Safenet SoftPK/SoftRemote

Whit Blauvelt's SoftRemote tips
Tim Wilson's tips (X.509)

Jean-Francois Nadeau's Practical Configuration (Road Warrior with PSK)
Terradon Communications' PDF (Road Warrior with PSK)
Seaan.net's PDF (Road Warrior to Subnet, with PSK)
Red Baron Consulting's PDF (Road Warrior with X.509)

Back to chart

For Other Implementations

6Wind

French page with configs (X.509)

Back to chart

Alcatel Timestep

Alain Sabban's settings (PSK or PSK road warrior; through static NAT)
Derick Cassidy's configs (PSK)
David Kerry's Timestep settings (PSK)
Kevin Gerbracht's ipsec.conf (X.509)

Back to chart

AshleyLaurent VPCom

Successful interop report, no details

Back to chart

Borderware

Philip Reetz' configs (PSK)
Borderware server does not support FreeS/WAN road warriors
Older Borderware may not support Diffie Hellman groups 2, 5

Back to chart

Check Point VPN-1 or FW-1

AERAsec's Firewall-1 NG site (PSK, X.509, Road Warrior with X.509, other algorithms)
     AERAsec's detailed Check Point-FreeS/WAN support matrix
Checkpoint.com PDF: Linux as a VPN Client to FW-1 (PSK)
PhoneBoy's Check Point FAQ (on Check Point only, not FreeS/WAN)

Back to chart

Cisco

French page with configs for Cisco IOS, PIX and VPN 3000 (X.509)

Back to chart

F-Secure

Text goes here.

Back to chart

Gauntlet GVPN

Richard Reiner's ipsec.conf (PSK)
Might work without that pesky firewall... (PSK)

Back to chart

IBM AS/400

Richard Welty's tips and tricks

Back to chart

Intel Shiva LANRover / Net Structure

Snowcrash's configs (PSK)
Old configs from an interop (PSK)
The day Shiva tickled a Pluto bug (PSK)
     Follow up: success!

Back to chart

Linksys

As tunnel endpoint

Ken Bantoft's instructions (Road Warrior with PSK)
Nate Carlson's caveats

In IPsec passthrough mode

Sample HOWTO through a Linksys Router
Nadeem Hasan's configs
Brock Nanson's tips

Back to chart

Lucent

Partial success report; see also the next message in thread

Back to chart

Netasq

French page with configs (X.509)

Back to chart

Netcelo

French page with configs (X.509)

Back to chart

Netscreen

Errol Neal's settings (PSK)
Corey Rogers' configs (PSK, no PFS)
Jordan Share's configs (PSK, 2 subnets, through static NAT)
Set src proxy_id to your protected subnet/mask
French page with ipsec.conf, Netscreen screen shots (X.509, may need to revert to PSK...)

A report of a company using Netscreen with FreeS/WAN on a large scale (FreeS/WAN road warriors?)

Back to chart

Nortel Contivity

JJ Streicher-Bremer's mini HOWTO for old new software. (PSK with two subnets)
French page with configs (X.509). This succeeds using the above X.509 tip.

Back to chart

Radguard

Marko Hausalo's configs (PSK). Note: These do create a connection, as you can see by "IPsec SA established".
Claudia Schmeing's comments

Back to chart

Raptor (NT or Solaris)

Peter Mazinger's settings (PSK)
Peter Gerland's configs (PSK)
Charles Griebel's configs (PSK).
Lumir Srch's tips (PSK)

John Hardy's configs (Manual)
Older Raptors want 3DES keys in 3 parts (Manual).
Different keys for each direction? (Manual)

Back to chart

Redcreek Ravlin

Back to chart

SonicWall

Wouter's config (PSK)
Dilan Arumainathan's configuration (PSK)
Dariush's setup... only opens one way (PSK)

Back to chart

Sun Solaris

Text goes here.

Back to chart

Symantec

Andreas Steffen's configs for Symantec 200R (PSK)

Back to chart

Watchguard Firebox

WatchGuard's HOWTO (PSK)
Ronald C. Riviera's Settings (PSK)
Max Enders' Configs (Manual)

Old known issue with auto keying
Tips on key generation and format (Manual)

Back to chart

Xedia Access Point/QVPN

Hybrid IPsec/L2TP connection settings (X.509)
Xedia's LAN-LAN links don't use multiple tunnels
     That explanation, continued

Back to chart


Contents Previous Next