The FreeS/WAN project needs you! We rely on the user community to keep up to date. Mail users@lists.freeswan.org with your interop success stories.
Please note: Most of our interop examples feature Linux FreeS/WAN 1.x config files. You can convert them to 2.x files fairly easily with the patch in our Upgrading Guide.
| FreeS/WAN VPN | Road Warrior | OE | ||||
| PSK | RSA Secret | X.509 (requires patch) | Manual Keying | |||
| More Compatible | ||||||
| isakmpd (OpenBSD) | Yes | Yes | Yes | No | ||
| Kame (FreeBSD, NetBSD) | Yes | Yes | Yes | No | ||
| McAfee VPN was PGPNet | Yes | Yes | Yes | Yes | No | |
| Microsoft Windows 2000/XP | Yes | Yes | with FreeS/WAN as Warrior | No | ||
| SSH Sentinel | Yes | Yes | Yes | No | ||
| Safenet SoftPK /SoftRemote | Yes | Yes | Yes | No | ||
| Other | ||||||
| 6Wind | Yes | No | ||||
| Alcatel Timestep | Yes | No | ||||
| Apple Macintosh System 10+ | Maybe | No | ||||
| AshleyLaurent VPCom | Yes | No | ||||
| Borderware | Yes | No | No | |||
| Check Point FW-1/VPN-1 | Yes | Yes | Yes | No | ||
| Cisco with 3DES | Yes | Maybe | No | |||
| F-Secure | Yes | Yes | Yes | No | ||
| Gauntlet GVPN | Yes | No | ||||
| IBM AIX | Yes | Maybe | No | |||
| IBM AS/400 | Yes | No | ||||
| Intel Shiva LANRover/Net Structure | Yes | No | ||||
| Linksys | Maybe | No | Yes | No | ||
| Lucent | Partial | No | ||||
| Netasq | Yes | No | ||||
| netcelo | Yes | No | ||||
| Netgear fvs318 | Yes | No | ||||
| Netscreen 100 or 5xp | Yes | Maybe | No | |||
| Nortel Contivity | Partial | Yes | No | |||
| RadGuard | Yes | No | ||||
| Raptor | Yes | Yes | No | |||
| Redcreek Ravlin | Yes/Partial | No | ||||
| SonicWall | Yes | No | No | |||
| Sun Solaris | Yes | No | ||||
| Symantec | Yes | No | ||||
| Watchguard Firebox | Yes | Yes | No | |||
| Xedia Access Point /QVPN | Yes | No | ||||
| PSK | RSA Secret | X.509 (requires patch) | Manual Keying | |||
| FreeS/WAN VPN | Road Warrior | OE | ||||
| Yes | People report that this works for them. | 
| [Blank] | We don't know. | 
| No | We have reason to believe it was, at some point, not possible to get this to work. | 
| Partial | Partial success. For example, a connection can be created from one end only. | 
| Yes/Partial | Mixed reports. | 
| Maybe | We think the answer is "yes", but need confirmation. | 
Vanilla FreeS/WAN implements these parts of the IPSec specifications.
You can add more with Super FreeS/WAN, particularly with the algorithm patches, but what we offer may be enough for many users.
We propose a set of proposals which are not user-adjustable, but cover the full set of what we can offer:
We propose Diffie Hellman groups 5 and 2 (in that order), and MD5 and SHA-1 hashes. We always propose: Triple DES encryption, Perfect Forward Secrecy, ...
This yields the proposal grid:
OpenBSD FAQ: Using
 IPsec
 Hans-Joerg Hoexer's interop Linux-OpenBSD (PSK)
 Skyper's configuration
 (PSK)
 French page with configs (X.509)
Kame homepage, with FAQ
 NetBSD's IPSec FAQ
 Itojun's Kame-FreeS/WAN interop tips (PSK)
 Ghislaine
 Labouret's French page with links to matching FreeS/WAN and Kame
 configs (RSA)
     
Ghislaine's post explaining some peculiarities
 Frodo's Kame-FreeS/WAN interop (X.509)
 Using Kame as a WAVEsec client
 Hans-Joerg Hoexer's Guide for Linux-PGPNet (PSK)
 Kai Martius' instructions using RSA Key-Extractor Tool (RSA)
     Christian
 Zeng's page (RSA) based on Kai's work. English or German.
 Oscar Delgado's PDF (X.509, no configs)
 Ryan's HOWTO
 for FreeS/WAN-PGPNet (X.509). Through a Linksys Router with IPsec
 Passthru enabled.
 Jean-Francois
 Nadeau's Practical Configuration (Road Warrior with PSK)
 Wouter
 Prins' HOWTO (Road Warrior with X.509)
 Rekeying problem with FreeS/WAN and older PGPNets
DHCP over IPSEC HOWTO for FreeS/WAN (requires X.509 and dhcprelay patches)
 Jean-Francois
 Nadeau's Net-net Configuration (PSK)
 Telenor's
 Node-node Config (Transport-mode PSK)
 Marcus Mueller's HOWTO using his
 VPN config tool (X.509). Tool also works with PSK.
 Nate Carlson's HOWTO using same tool (Road Warrior with X.509).
 Unusually, FreeS/WAN is the Road Warrior here.
 Oscar Delgado's PDF (X.509, no configs)
 Microsoft's page on Win2k TCP/IP security features
 Microsoft's Win2k IPsec debugging tips
 MS VPN may fall back to 1DES
 SSH's
 Sentinel-FreeSWAN interop PDF (X.509)
 Nadeem Hassan's SUSE-to-Sentinel article (Road warrior with X.509)
 O-Zone's Italian HOWTO (Road Warrior, X.509, DHCP)
 Whit Blauvelt's SoftRemote tips
 Tim Wilson's tips (X.509)
 Jean-Francois
 Nadeau's Practical Configuration (Road Warrior with PSK)
 Terradon Communications' PDF (Road Warrior with PSK)
 Seaan.net's PDF (Road Warrior to Subnet, with PSK)
 Red Baron Consulting's PDF (Road Warrior with X.509)
French page with configs (X.509)
 Alain Sabban's settings (PSK or PSK road warrior; through static NAT)
 Derick Cassidy's configs (PSK)
 David Kerry's Timestep settings (PSK)
 Kevin Gerbracht's ipsec.conf (X.509)
 To use Appletalk over IPsec tunnels, run it over tcp/ip.
     
Or use Open Door Networks' Shareway IP tool, described here.
Successful interop report, no details
 Philip Reetz' configs (PSK)
 Borderware server does not support FreeS/WAN road warriors
 Older Borderware may not support Diffie Hellman groups 2, 5
 AERAsec's Firewall-1 NG site (PSK, X.509, Road Warrior with X.509,
 other algorithms)
     
 AERAsec's detailed Check Point-FreeS/WAN support matrix
 Checkpoint.com PDF: Linux as a VPN Client to FW-1 (PSK)
 PhoneBoy's Check Point FAQ (on
 Check Point only, not FreeS/WAN)
 Chris Harwell's tips FreeS/WAN configs (PSK)
 Daniel Tombeil's configs (PSK)
 SANS
 Institute HOWTO (PSK). Detailed, with extensive references.
 Short HOWTO
 (PSK)
 French page with configs for Cisco IOS, PIX and VPN 3000 (X.509)
 Dave McFerren's sample configs (PSK)
 Wolfgang Tremmel's sample configs (PSK road warrior)
 Old doc from Pete Davis, with William Watson's updated Tips (PSK)
Some PIX specific information:
 Scott's ipsec.conf for PIX (PSK, FreeS/WAN side only)
 Greg Robinson's PIX FreeS/WAN settings (PSK)
 Rick Trimble's PIX and FreeS/WAN settings (PSK)
 Cisco VPN support
 page
 Cisco IPsec information page
pingworks.de's
 "Connecting F-Secure's VPN+ to Linux FreeS/WAN" (PSK road warrior)
     Same thing
 as PDF
 Success report, no detail (PSK)
 Success report, no detail (Manual)
 Richard Reiner's ipsec.conf (PSK)
 Might work without that pesky firewall... (PSK)
 IBM's "Built-In Network Security with AIX" (PSK, X.509)
 IBM's tip: importing Linux FreeS/WAN settings into AIX's ikedb
 (PSK)
 Richard Welty's tips and tricks
 Snowcrash's configs
 (PSK)
 Old configs from an
 interop (PSK)
 The day Shiva tickled a Pluto bug (PSK)
     
 Follow up: success!
 Ken Bantoft's
 instructions (Road Warrior with PSK)
 Nate Carlson's caveats
 Sample HOWTO
 through a Linksys Router
 Nadeem Hasan's configs
 Brock Nanson's tips
Partial success report; see also the next message in thread
French page with configs (X.509)
French page with configs (X.509)
 Errol Neal's settings (PSK)
 Corey Rogers' configs (PSK, no PFS)
 Jordan Share's configs (PSK, 2 subnets, through static NAT)
 Set src proxy_id to your protected subnet/mask
 French page with ipsec.conf, Netscreen screen shots (X.509, may need to
 revert to PSK...)
A report of a company using Netscreen with FreeS/WAN on a large scale (FreeS/WAN road warriors?)
 JJ Streicher-Bremer's mini HOWTO for old new software. (PSK with two
 subnets)
 French page with configs (X.509). This succeeds using the above
 X.509 tip.
 Marko Hausalo's configs (PSK). Note: These do create a connection,
 as you can see by "IPsec SA established".
 Claudia Schmeing's comments
 Peter Mazinger's settings (PSK)
 Peter Gerland's configs (PSK)
 Charles Griebel's configs (PSK).
 Lumir Srch's tips (PSK)
 John Hardy's configs (Manual)
 Older Raptors want 3DES keys in 3 parts (Manual).
 Different keys for each direction? (Manual)
 Wouter's config
 (PSK)
 Dilan Arumainathan's configuration (PSK)
 Dariush's setup...
 only opens one way (PSK)
Aleks Shenkman's configs (Manual in transport mode) sparc 64 stuff goes where?
Andreas Steffen's configs for Symantec 200R (PSK)
 WatchGuard's HOWTO (PSK)
 Ronald C. Riviera's Settings (PSK)
 Max Enders' Configs (Manual)
 Old known issue with auto keying
 Tips on key generation and format (Manual)
 Hybrid IPsec/L2TP connection settings (X.509)
 Xedia's LAN-LAN links don't use multiple tunnels
     
 That explanation, continued