- StrongSwan
Infobox Software
name = strongSwan
caption =
author =
developer = Andreas Steffen & Martin Willi
released =
latest release version = 4.2.7
latest release date =September 18 ,2008
latest preview version =
latest preview date =
operating system =Linux
platform =
language =
status =
genre =IPsec
license =GNU General Public License
website = [http://www.strongswan.org/ www.strongswan.org]strongSwan is a complete
IPsec implementation forLinux 2.4 and 2.6 kernels.It is a descendant of the
FreeS/WAN project, and continues to be released under the GPL license. The project is actively maintained by Andreas Steffenwho is a professor for Security in Communications at the [http://www.hsr.ch University of Applied Sciences Rapperswil] in Switzerland.The focus of the strongSwan project is on strongauthentication mechanisms usingX.509 public key certificate s and optional secure storage ofprivate key s onsmartcard s through a standardized PKCS#11 interface. It supportscertificate revocation list s and theOnline Certificate Status Protocol (OCSP). A unique feature is the use ofX.509 attribute certificate s to implement advancedaccess control schemes based on group memberships.strongSwan has an easy and straightforward approach to configuration and interoperatessmoothly with most other
IPsec implementations including variousMicrosoft Windows andMac OS X VPN clients.The modular strongSwan 4.2 branch fully implements the
IKEv2 protocol defined by RFC 4306. Software architect and main developer of the IKEv2 keying daemon is Martin Willi. NAT traversal for IKEv2 was contributed by Tobias Brunner and Daniel Röthlisberger. The IKEv2 Mediation Service defined in [http://tools.ietf.org/html/draft-brunner-ikev2-mediation draft-brunner-ikev2-mediation] was implemented by Tobias Brunner.UML simulation environment
strongSwan comes with an easy-to-use simulation environment based on
User-mode Linux . A network of eight virtual hosts allows the user to enact a multitude of site-to-site androadwarrior VPN scenarios.External links
* [http://www.strongswan.org/ strongSwan website]
* [http://www.strongswan.org/uml/ strongSwan UML testing environment]
* [http://www.strongswan.org/docs/LinuxTag2007-strongSwan.pdf LinuxTag 2007 Paper: strongSwan - the new IKEv2 VPN Solution]
* [http://www.strongswan.org/docs/LinuxTag2005-strongSwan.pdf LinuxTag 2005 Paper: Advanced Features of Linux strongSwan]
* [http://www.strongswan.org/uml/DFN_UML.pdf DFN 2005 Paper: Advanced Network Simulation under User-Mode Linux]
* [http://www.mudynamics.com/news/press/pr091908.html Mu Dynamics discovers, remediates leading open source VPN vulnerability: StrongSwan IKEv2 Denial Of Service]
Wikimedia Foundation. 2010.