Linux SoftwareSystemNetworkingstrongSwan 4.0.5

strongSwan 4.0.5


strongSwan is an OpenSource IPsec implementation for the Linux operating system
Developer:   Andreas Steffen
      more software by author →
Price:  0.00
License:   GPL (GNU General Public License)
File size:   2475K
Language:   
OS:   
Rating:   0 /5 (0 votes)
Your vote:  
enlarge screenshot


strongSwan is an OpenSource IPsec implementation for the Linux operating system. strongSwan is based on the discontinued FreeS/WAN project and the X.509 patch which we developped over the last three years.

In order to have a stable IPsec platform to base our future extensions of the X.509 capability on, we decided to lauch the strongSwan project.

Here are some key features of "strongSwan":
  • runs both on Linux 2.4 (KLIPS) and Linux 2.6 (native IPsec) kernels
  • strong 3DES, AES, Serpent, Twofish, or Blowfish encryption
  • Authentication based on X.509 certificates or preshared keys
  • Powerful IPsec policies based on wildcards or intermediate CAs
  • Retrieval and local caching of Certificate Revocation Lists via HTTP or LDAP
  • Full support of the Online Certificate Status Protocol (OCSP, RCF 2560).
  • Optional storage of RSA private keys on smartcards or USB crypto tokens
  • Smartcard access via standardized PKCS #11 interface
  • PKCS #11 proxy function offering RSA decryption services via whack
  • NAT-Traversal (RFC 3947) and support of Virtual IPs and IKE Mode Config
  • CA management (OCSP and CRL URIs, default LDAP server)
  • Dead Peer Detection (DPD, RFC 3706)
  • Group policies based on X.509 attribute certificates ( RFC 3281)
  • Generation of default self-signed certificates during strongSwan setup

    What's New in 2.8.0 Stable Release:
  • The implementation of the IKE Mode Config push mode allows interoperability with Cisco VPN gateways.
  • By setting "modeconfig=push", strongSwan will wait for the peer to push down a virtual IP address that can be used within an IPsec tunnel.
  • The default value of the new keyword is "modeconfig=pull".
  • The command "ipsec statusall" now shows "DPD active" for all ISAKMP Security Associations that are under active Dead Peer Detection control.

    What's New in 4.0.5 Development Release:
  • Major improvements were done for the monitoring, debugging, and logging functions for the IKEv2 keying daemon.
  • Informational console output is now available during connection startup.
  • IKEv1 Mode Config Push mode was backported from strongswan 2.8.0.
    tags for the  mode config  config push  push mode  peer detection  dead peer  policies based  ike mode  

    Download strongSwan 4.0.5


     http://download.strongswan.org/strongswan-2.8.0.tar.bz2
     http://download.strongswan.org/strongswan-4.0.5.tar.bz2


    Authors software

    strongSwan 4.0.5 (by Andreas Steffen)
    strongSwan is an OpenSource IPsec implementation for the Linux operating system


    Similar software

    strongSwan 4.0.5 (by Andreas Steffen)
    strongSwan is an OpenSource IPsec implementation for the Linux operating system

    Openswan 2.4.6 (by The Openswan project)
    Openswan is an implementation of IPsec for the Linux operating system

    IPsec-Tools 0.6.6 (by Michal Ludvig)
    IPsec-Tools is a port of KAME's IPsec utilities to the Linux-2.6 IPsec implementation

    FreeS/WAN 2.06 (by John Gilmore)
    FreeS/WAN is an implementation of IPSEC & IKE for Linux

    Template::Tutorial 2.15 (by Andy Wardley)
    Template::Tutorial are template toolkit tutorials.

    This section includes tutorials on using the Template Toolkit

    DX-PKI 1.9.0 (by Idealx)
    IDX-PKI is an Open Source implementation of a Public Key Infrastructure which aims to be IETF compliant for PKIX recommendation

    Wolverine Firewall and VPN Server 2.01.1008 RC1 (by Joshua Jackson)
    Wolverine is an embedded distribution of Linux designed to function as a firewall and VPN server

    KVpnc 0.8.7 (by Christoph Thielecke)
    KVpnc is a KDE frontend for various vpn clients

    Pam_p11 0.1.2 (by OpenSC Developers)
    Pam_p11 is a plugable authentication module (pam) package for using crpytographic tokes such as smart cards and usb crypto tokens for

    xca 0.5.1 (by Christian Hohnstaedt)
    This application is a graphical user interface to OpenSSL, RSA public keys, certificates, signing requests and revokation lists.

    T


    Other software in this category

    Nmap 4.20 (by Fyodor)
    Nmap is a utility for network exploration or security auditing

    iptables 1.3.7 (by Harald Welte)
    iptables and netfilter are building blocks of a framework inside the Linux 2.4.x and 2.6.x kernel

    Linux Bandwidth Arbitrator 9.62 (by astormchaser)
    Linux Bandwidth Arbitrator allows beginning-to-advanced network administrators to control bandwidth

    Ettercap 0.7.3 (by ALoR NaGA)
    Ettercap is a network sniffer/interceptor/logger for ethernet LANs

    rdesktop 1.5.0 (by matthewc)
    rdesktop is an open source client for Windows NT Terminal Server and Windows 2000/2003 Terminal Services, capable of natively speakin

  •     search


    Featured Software

    jEdit 4.3 pre8
    jEdit is an Open Source text editor written in Java

    Opera 9.02
    Surf the Internet in a safer, faster, and easier way with Opera browser

    GNU Aspell 0.60.4
    GNU Aspell is a Free and Open Source spell checker designed to eventually replace Ispell


    Subscribe in Rojo
    Google Reader
    Add to My Yahoo!

    Add to My AOL
    Subscribe with Bloglines
    Subscribe in NewsGator Online
    Add 'nixbit linux software' to Newsburst from CNET News.com
    del.icio.us nixbit linux software


    Top tags