Re: CERT and IPSEC and SSH

From: Casper H.S. Dik (Casper.Dik_at_Sun.COM)
Date: 09/29/04


Date: 29 Sep 2004 09:07:40 GMT

erik@tfb.com (Erik Magnuson) writes:

>Has any effort been made to document the interoperability of Solaris
>IPSEC with other implementations of IPSEC? From what I've read in the
>Sol 9 documentation, setting up IPSEC to work with another Solaris
>host seems to be straightforward, but many questions remain with other
>implementations (e.g. some of the firewall appliances).

Solaris 9 IPsec is fully RFC compliant, including
manual keying and IKE it is known to interoperate with
Windows IPsec.

Solaris 8 IPsec does not support IKE and therefor
does not interoperate with Windows (the latter requires
IKE)

I don't think we've tested any firewall appliances; for
one, the Cisco VPN solutions use IPsec but have some
additional stuff added inthe authentication phase.

Solaris 9 IPsec also misses NAT support which makes
using it behind a NAT gateway impossible; this is
needed in many VPN-from-home situations.

Casper