|Revision 0.9.96||2007-02-26||Revised by: RS|
|OpenSSL needs file: crlnumber|
|Revision 0.9.95||2005-09-03||Revised by: RS|
|Added iptables rule setting the MSS and one minor correction|
|Revision 0.9.94||2005-07-19||Revised by: RS|
|Added some remarks about routing|
|Revision 0.9.93||2005-03-3||Revised by: RS|
|fwd-policy corrected, p12 added|
|Revision 0.9.92||2005-02-1||Revised by: RS|
|Revision 0.9.91||2005-01-31||Revised by: RS|
|/etc/ipsec.conf replaced by /etc/setkey.conf|
|Revision 0.9.9||2004-12-22||Revised by: RS|
Changed Document structure|
|Revision 0.9.6||2004-01-28||Revised by: RS|
|Revision 0.9.5||2004-01-08||Revised by: RS|
|Added Compilation of certpatch and keyconv|
|Revision 0.9.4||2003-08-28||Revised by: RS|
|Revision 0.9.3||2003-08-22||Revised by: RS|
|Fixed a typo|
|Revision 0.9.2||2003-08-19||Revised by: RS|
|Fixed a typo|
|Revision 0.9.1||2003-08-18||Revised by: RS|
|Revision 0.9.0||2003-08-15||Revised by: RS|
|Added: Using the OpenBSD isakmpd|
|Revision 0.8.3||2003-05-13||Revised by: RS|
|Further typos corrected. Some sentences rephrased.|
|Revision 0.8.2||2003-05-03||Revised by: RS|
|Revision 0.8.1||2003-04-30||Revised by: RS|
|added chapter covering certificates|
|Revision 0.8||2003-04-18||Revised by: RS|
This HowTo will cover the basic and advanced steps setting up a VPN using IPsec based on the Linux Kernels 2.6. Since there is a vast amount of documentation available for the Linux Kernel 2.4, this HowTo will concentrate on the new IPsec Features in the 2.6 kernel.
The latest version of this document can always be found at The Linux Documentation Project and at the official homepage http://www.ipsec-howto.org.
I have used numeruos HowTos in the past. Most were very valuable to me. When the new IPsec features in the Linux Kernel were implemented I started to play around using them. Soon I found out that only very little documentation exists. That started me writing this HowTo.
This document is broken down into 7 chapters.
- Section 1: Introduction
- Section 2: Theory
IPsec theory. Essentially the IPsec protocols.
- Section 3: Openswan
This section will describe how to setup Openswan on the Kernel 2.6.
- Section 4: Racoon running on Linux Kernel 2.6
This section describes how to setup an IPsec VPN using the KAME tools setkey and racoon. This now includes NAT-Traversal.
- Section 5: Isakmpd running on Linux Kernel 2.6
This section describes how to setup an IPsec VPN using OpenBSD isakmpd IKE daemon.
- Section 6: Generating X.509 Certificates
This section describes how to generate X.509 Certificates using the openssl-Command.
- Section 7: Advanced Configuration
This section gives some hints on XAUTH and on useful iptables-rules.
Copyright (c) 2003 Ralf Spenneberg
Please freely copy and distribute (sell or give away) this document in any format. It's requested that corrections and/or comments be fowarded to the document maintainer. You may create a derivative work and distribute it provided that you:
Send your derivative work (in the most suitable format such as sgml) to the LDP (Linux Documentation Project) or the like for posting on the Internet. If not the LDP, then let the LDP know where it is available.
License the derivative work with this same license or use GPL. Include a copyright notice and at least a pointer to the license used.
Give due credit to previous authors and major contributors.
If you're considering making a derived work other than a translation, it's requested that you discuss your plans with the current maintainer.
The author assumes no responsibility for anything done with this document, nor does he make any warranty, implied or explicit. If your dog dies, the author may not be made responsible!