| IKE encryption | |||||||||
|---|---|---|---|---|---|---|---|---|---|
|
Method:
|
DES | BLOWFISH | 3DES | CAST | AES | SERPENT | TWOFISH | SSH_PRIVATE | |
| Check Point VPN-1 NG FP2 |
|
no |
|
yes (128) |
(256) |
no | no |
|
|
| Check Point VPN-1 NGX R61 | yes | no |
yes |
yes (128) |
yes (128,256) |
no |
no |
no |
|
| Linux FreeS/WAN 1.96 |
|
no |
|
no |
|
no | no |
|
|
| Linux FreeS/WAN 1.98b | no | yes1 | yes | yes1 | yes1 (128,256) |
yes1 | yes1 | yes1 | |
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 | yes (56) |
yes |
yes |
yes |
yes1 (128,256) |
yes |
yes |
no |
|
| Linux FreeS/WAN 1.96 vs. Check Point VPN-1 NG FP2 |
no | no | yes | no | no | no | no | no | |
| Linux FreeS/WAN 1.98b vs. Check Point VPN-1 NG FP2 |
|
|
|
working2
(128) |
working2
(256) |
no |
|
|
|
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 vs. Check Point VPN-1 NGX R61 | noa) |
no |
working |
nob) |
working
(128,256) |
no |
no |
no |
|
| IKE integrity | IKE authentication | ||||||
|---|---|---|---|---|---|---|---|
|
Method:
|
MD5 | SHA1 | SHA2 | Pre-Shared Secret | Public Key Signatures | ||
| Check Point VPN-1 NG FP2 Check Point VPN-1 NGX R61 |
yes |
|
|
yes | yes | ||
| Linux FreeS/WAN 1.96 |
yes |
|
|
yes | yes3 | ||
| Linux FreeS/WAN 1.98b | yes | yes |
(256,512) |
yes | yes3 | ||
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 | yes |
yes |
noa) |
yes |
yes |
||
| Linux FreeS/WAN 1.96 vs. Check Point VPN-1 NG FP2 | working | incompatible | no | working | working | ||
| Linux FreeS/WAN 1.98b vs. Check Point VPN-1 NG FP2 |
|
|
no | working | working | ||
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 vs. Check Point VPN-1 NGX R61 | working |
working |
no |
working |
working | ||
| Diffie-Hellman Groups | Perfect Forward Secrecy |
|||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 768 (1) |
1024 (2) |
1536 (5) |
2048 (14) |
3072 (15) |
4096 (16) |
6144 (17) |
8196 (18) |
|||||
| Check Point VPN-1 NG FP2 |
yes |
|
|
no | no | no | no |
no |
yes | |||
| Check Point VPN-1 NGX R61 |
yes |
|
|
yes | no | no | no |
no |
yes | |||
| Linux FreeS/WAN 1.96 | no |
|
|
no | no | no | no | no | yes | |||
| Linux FreeS/WAN 1.98b | no |
yes |
|
yes1 | yes1 | yes1 | no | no | yes | |||
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 | no |
yes |
yes |
yes |
yes |
yes |
yes |
yes |
yes |
|||
| Linux FreeS/WAN 1.96 vs. Check Point VPN-1 NG FP2 | no |
working |
working |
no |
no |
no |
no |
no |
incompatible |
|||
| Linux FreeS/WAN 1.98b vs. Check Point VPN-1 NG FP2 | no |
working |
working |
no |
no |
no |
no |
no |
working*) |
|||
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 vs. Check Point VPN-1 NGX R61 | no |
working |
working |
working |
no |
no |
no |
no |
working*) | |||
| Payload encryption | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
Method:
|
DES (2) |
BLOWFISH (7) |
3DES (3) |
CAST (6) |
AES |
SERPENT | TWOFISH | SSH_PRIVATE | NULL (11) |
|
| Check Point VPN-1 NG FP2 |
(40,56) |
no |
|
yes (40,128) |
(128,256) |
no | no |
|
? |
|
| Check Point VPN-1 NGX R61 | yes (40,56) |
no |
yes |
yes (40,128) |
yes (128,256) |
no |
no |
no |
yes |
|
| Linux FreeS/WAN 1.96 |
|
no |
|
no |
|
no | no |
|
? |
|
| Linux FreeS/WAN 1.98b | no | yes1 | yes | yes1 | yes1 (128,256) |
yes1 | yes1 | yes1 | ? |
|
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 | yes |
yes |
yes |
yes |
yes (128,256) |
yes |
yes |
no |
yes |
|
| Linux FreeS/WAN 1.96 vs. Check Point VPN-1 NG FP2 | no | no | working | no | no | no | no | no | ? |
|
| Linux FreeS/WAN 1.98b vs. Check Point VPN-1 NG FP2 |
|
|
|
working (40,128) |
working (128,256) |
|
|
|
? |
|
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 vs. Check Point VPN-1 NGX R61 | working (56) |
no |
working |
nob) |
working
(128,256) |
no |
no |
no |
noa) |
|
| Payload integrity | Compression | |||||
|---|---|---|---|---|---|---|
|
Method:
|
MD5 | SHA1 | SHA2 | DEFLATE | ||
| Check Point VPN-1 NG FP2 Check Point VPN-1 NGX R61 |
yes |
|
|
yes | ||
| Linux FreeS/WAN 1.96 | yes |
|
|
yes | ||
| Linux FreeS/WAN 1.98b | yes | yes |
(256,512) |
yes | ||
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 | yes |
yes |
no |
yes |
||
| Linux FreeS/WAN 1.96 vs. Check Point VPN-1 NG FP2 | working | incompatible | no | working | ||
| Linux FreeS/WAN 1.98b vs. Check Point VPN-1 NG FP2 |
|
|
no | working | ||
| kernel 2.6.17-1.2157_FC5 / openswan 2.4.4-1.1.2.1 vs. Check Point VPN-1 NGX R61 | working |
working |
no |
incompatiblea) |
||