Linux FreeSWAN HTML documents

Automatically generated Table of Contents
Bug reports to the mailing list: linux-ipsec@clinet.fi

Section headings printed, indentation shows structure [] items are labels you can jump to =================================================== HTML file: index.html --------------------------------------------------- Linux FreeS/WAN Index file ------------------------------------------ Files most users should read ------------------------------------------ Distribution text files ------------------------------------------ Project background information ------------------------------------------ Reference information ------------------------------------------ Specialised information =================================================== HTML file: overview.html --------------------------------------------------- Linux FreeS/WAN Overview ------------------------------------------ Introduction Other documents in the distribution About the RFCs (Internet Request For Comment documents) ------------------------------------------ The Role of IPSEC Services provided Security protocols at other levels Advantages of IPSEC Limitations of IPSEC IPSEC is not end-to-end IPSEC cannot do everything IPSEC cannot be secure if your system isn't Some uses of IPSEC Using authentication without encryption Using "unnecessary" encryption to block ------------------------------------------ IPSEC projects Vendor Groups VPN Consortium S/WAN (Secure Wide Area Networks) Linux FreeS/WAN Other projects ------------------------------------------ IPSEC Services, AH and ESP The Authentication Header (AH) Keyed MD5 and Keyed SHA Sequence numbers Encapsulated Security Payload (ESP) ------------------------------------------ IPSEC modes Tunnel mode Transport mode ------------------------------------------ FreeS/WAN parts KLIPS: Kernel IPSEC Support The Pluto daemon The ipsec(8)command Linux FreeS/WAN configuration file ------------------------------------------ Key management Currently Implemented Methods Manual keying Automatic keying Methods not yet implemented Unauthenticated key exchange The Internet default shared secret Key exchange using DNS Key exchange using a PKI Photuris SKIP =================================================== HTML file: roadmap.html --------------------------------------------------- Distribution Roadmap
What's Where in Linux FreeS/WAN ------------------------------------------ Subsystems ------------------------------------------ Top directory ------------------------------------------ Documentation ------------------------------------------ KLIPS ------------------------------------------ Pluto ------------------------------------------ Utils ------------------------------------------ Libraries FreeS/WAN Library Imported Libraries =================================================== HTML file: setup.html --------------------------------------------------- Linux FreeS/WAN Setup ------------------------------------------ Setting up a secure tunnel to create a VPN ------------------------------------------ Our example network ------------------------------------------ Installation steps Before starting the install Building the software The ipsec.conf(5) configuration file Editing connections in /etc/ipsec.conf Creating keys with ranbits Putting secrets in /etc/ipsec.secrets Setting up interfaces Matching numbers Testing the installation Manually keyed test Testing with tcpdump Testing Automatic connections =================================================== HTML file: configuration.html --------------------------------------------------- Linux FreeS/WAN Configuration ------------------------------------------ RTFM ------------------------------------------ Setting up connections at boot time ------------------------------------------ Using manual keying in production ------------------------------------------ Variations on IPSEC
Extruded Subnets Road Warrior support Dynamic Network Interfaces Basics Boot Time Change Time Unencrypted tunnels =================================================== HTML file: RFCs.html --------------------------------------------------- Linux FreeS/WAN RFC List ------------------------------------------ The RFCs.tar.gz Distribution File ------------------------------------------ Other sources for RFCs & Internet drafts RFCs Internet Drafts FIPS standards Document CDs ------------------------------------------ What's in the RFCs.tar.gz bundle? Overview RFCs Basic protocols Key management Details of various things used Older RFCs which may be referenced RFCs for secure DNS service, which IPSEC may use RFCs labelled "experimental" Related RFCs =================================================== HTML file: debugging.html --------------------------------------------------- Linux FreeS/WAN Troubleshooting ------------------------------------------ Problem Reporting ------------------------------------------ Test with ipsec manual before going to auto [ noauto ] [ flakyauto ] [ nomanual ] ------------------------------------------ Information available on your system ifconfig reports for KLIPS debugging ------------------------------------------ Testing Between Gateways =================================================== HTML file: compatibility.html --------------------------------------------------- Linux FreeS/WAN compatibility Guide ------------------------------------------ Implemented parts of the IPSEC Specification In Linux FreeS/WAN Not (yet) in Linux FreeS/WAN ------------------------------------------ Intel Linux other than Redhat 5.2 with 2.0.36 kernel Other 2.0.x Intel Kernels 2.1 and 2.2 Kernels ------------------------------------------ Linux distributions other than Redhat SuSE Linux 5.3 ------------------------------------------ CPUs other than Intel [ netwinder ] Corel Netwinder (StrongARM CPU) Alpha 64-bit processors Alpha with 2.2.x kernel version ------------------------------------------ Interoperation with other IPSEC implementations OpenBSD Cisco Routers Bay Networks switch Raptor Firewall on Windows NT Xedia Access Point/QVPN PGP 6.5 Mac and Windows IPSEC Client =================================================== HTML file: DES.html --------------------------------------------------- DES is Not Secure ------------------------------------------ Dedicated hardware breaks DES in a few days ------------------------------------------ Networks break DES in a few weeks ------------------------------------------ Moore's Law implies that breaks will get faster ------------------------------------------ We disable DES ------------------------------------------ 40-bits is laughably weak ------------------------------------------ Alternatives to DES =================================================== HTML file: exportlaws.html --------------------------------------------------- Cryptography Export Laws ------------------------------------------ US Law ------------------------------------------ What's wrong with export restrictions [ quotes ] ------------------------------------------ The Wassenaar Arrangement ------------------------------------------ Export status of Linux FreeS/WAN Help spread IPSEC around ------------------------------------------ Web References =================================================== HTML file: glossary.html --------------------------------------------------- Glossary for the Linux FreeS/WAN project ------------------------------------------ Jump to a letter ------------------------------------------ Other glossaries ------------------------------------------ Definitions [ 0 ] [ 3DES ] [ A ] [ active ] [ AES ] [ AH ] [ alicebob ] [ ASIO ] [ authentication ] [ auto ] [ B ] [ BIND ] [ birthday ] [ paradox ] [ block ] [ Blowfish ] [ brute ] [ BXA ] [ C ] [ CA ] [ CAST128 ] [ CBC ] [ mode ] [ challenge ] [ ciphertext ] [ collision ] [ CSE ] [ D ] [ DARPA ] [ DES ] [ DESX ] [ DH ] [ signature ] [ DNS ] [ E ] [ EAR ] [ ECB ] [ EDE ] [ Entrust ] [ EFF ] [ encryption ] [ ESP ] [ extruded ] [ F ] [ FIPS ] [ FSF ] [ G ] [ GCHQ ] [ GILC ] [ GTR ] [ GNU ] [ GPL ] [ H ] [ HMAC ] [ hybrid ] [ I ] [ IAB ] [ IDEA ] [ IESG ] [ IETF ] [ IKE ] [ IV ] [ IP ] [ masq ] [ IPv4 ] [ IPv6 ] [ IPSEC ] [ ISAKMP ] [ ITAR ] [ J ] [ K ] [ KLIPS ] [ L ] [ LDAP ] [ LIBDES ] [ Linux ] [ FreeSWAN ] [ M ] [ list ] [ middle ] [ manual ] [ MD4 ] [ MD5 ] [ meet ] [ digest ] [ N ] [ NAI ] [ NAT ] [ NIST ] [ nonce ] [ NSA ] [ O ] [ OTP ] [ carpediem ] [ P ] [ P1363 ] [ passive ] [ PFS ] [ PGP ] [ PGPI ] [ photuris ] [ PPTP ] [ PKI ] [ PKIX ] [ plaintext ] [ Pluto ] [ public ] [ Q ] [ R ] [ random ] [ RC4 ] [ RC6 ] [ replay ] [ RIPEMD ] [ rootCA ] [ RSA ] [ RSAco ] [ S ] [ SA ] [ SDNS ] [ sequence ] [ SHA ] [ SIGINT ] [ SKIP ] [ snake ] [ SSH ] [ SSHco ] [ SSL ] [ stream ] [ SWAN ] [ symmetric ] [ T ] [ TIS ] [ TLS ] [ traffic ] [ transport ] [ tunnel ] [ 2key ] [ U ] [ V ] [ virtual ] [ VPN ] [ VPNC ] [ W ] [ Wassenaar ] [ web ] [ X ] [ X509 ] [ Y ] [ Z ] =================================================== HTML file: bibliography.html --------------------------------------------------- Bibliography for the Linux FreeS/WAN project [ DNS ] [ puzzle ] [ comer ] [ EFF ] [ PGP ] [ practical ] [ kirch ] [ GTR ] [ schneier ] [ VPNbook ] [ stevens ] =================================================== HTML file: WWWref.html --------------------------------------------------- World Wide Web references for Linux FreeS/WAN ------------------------------------------ The Linux FreeS/WAN Project Web information [ rationale ] Distribution sites [ mirrors ] Archives of the project mailing list ------------------------------------------ The IPSEC Protocols IPSEC overview documents or slide sets IPSEC information in languages other than English RFCs and other reference documents ------------------------------------------ IPSEC Implementations Vendors of IPSEC Implementations Open source IPSEC implementations Other Linux IPSEC implementations IPSEC for BSD Unix Test sites for interoperability ------------------------------------------ Linux resources General Linux sites Linux Documentation Project Security for Linux Miscellaneous Linux information ------------------------------------------ Crypto and security resources Frequently Asked Question (FAQ) documents Tutorials Collections of crypto links Computer and network security Firewall links [ policy ] Cryptography law and policy Advocacy Security tools Lists of online cryptography papers Particularly interesting papers Crypto and security standards Links to home pages =================================================== HTML file: rationale.html --------------------------------------------------- ------------------------------------------ Deployment ------------------------------------------ ------------------------------------------ Why? ------------------------------------------ What You Can Do Related projects =================================================== HTML file: manpages.html --------------------------------------------------- FreeS/WAN manual pages ------------------------------------------ Files ------------------------------------------ Commands ------------------------------------------ Library routines =================================================== Linux FreeSWAN HTML documents

Automatically generated Table of Contents
Bug reports to the mailing list: linux-ipsec@clinet.fi

Docs & script by Sandy Harris