Everything2
Near Matches
Ignore Exact
Full Text
Everything2

FreeS/WAN

created by tlf

(thing) by arcterex (6.4 mon) (print)   ?   (I like it!) 2 C!s Wed Nov 28 2001 at 23:19:07

FreeS/WAN is software for the Linux Operating System that has the primary objective of making IPSEC encryption and tunneling widespread by providing source code to the world. The name stands for the "free secure wide area network".

FreeS/WAN allows you to build an encrypted tunnel through an insecure network, such as the internet. The packets of data that are passed between the two endpoints of the tunnel are encrypted, so that if the data is sniffed on the untrusted network, the contents are unreadable. Each tunnel endpoint is responsible for encrypting and decrypting the packets that are sent back and forth.

The result, as you may have guessed, is a Virtual Private Network or VPN.

The FreeS/WAN project was started in 1996 with the rather ambitious goal of securing 5% of the internet from wiretapping. So far the author (gnu@toad.com) has not achieved this goal, and realizes that this goal was a bit too ambitious, but is continuing to develop the software. As FreeS/WAN is not developed within the United States, none of the stupid US encryption export controls apply, so there is no restriction on strong encryption.

Three protocols are used:

The three main parts of FreeS/WAN are:

Another functionality that FreeS/WAN provides is the ability to handle road warriors, or VPN endpoints that are not at a fixed IP address. These could be users with a fixed location or DSL or Cable Modem users who are not given a static IP address by their provider.

Probably the most exciting part of FreeS/Wan is it's ability (coming RSN) to provide opportunistic encryption. This method of encryption is for any two systems configured to use opportunistic encryption to be able to create a VPN between them, even if the administrators have not configured the systems for it. Normally the two endpoints of a VPN have to be configured to "know" certain details about the other endpoint. With opportunistic encryption an endpoint can be a promiscuous little encryption whore, and establish a VPN with any other system that it finds that is also configured to use opportunistic encryption.

Freeswan is used in many projects and by many companies that need to use or sell secure communication. My company uses it in our embedded firewall device and are very happy with the results.


References:
FreeS/WAN's website is www.freeswan.org
A bit of history about FreeS/WAN is at http://www.toad.com/swan.html
Freeswan 1.9 documentation at http://freeswan.org/freeswan_trees/freeswan-1.9/doc/intro.html

printable version
chaos

IPsec The imaginary world where I make up things and they are true VPN NAT
Whore hunting encryption export controls GNU Privacy Guard United States
The USA has fucked up priorities DVD region lockout Opportunistic Encryption Canon patent five ideas a day to help you have hundreds
Virtual Private Network Ah Communications Decency Act Pluto
Skype First Day Cover Unicode European Alphabets Chap
Ottawa Linux Symposium mps Zakat Usagi
Y'know, if you log in, you can write something here, or contact authors directly on the site. Create a New User if you don't already have an account.
  Epicenter
Login
Password

password reminder
register

Everything2 Help

Cool Staff Picks
Things you could have written:
It's a jailbreak; we're free.
Strike
Friction Baby
brachistochrone
June 30, 2006
Song of the Sausage Creature
the death of a child
Hilbert Hotel
A short history in a long scar
Advice the KJV Bible has to give about Everything
learning to juggle
directed evolution
Strange things homeless people have said to me
New Writeups
doctor wilson
Soup, of the green variety(recipe)
Ctrl Y
cognitive dissonance(fiction)
SharQ
Gone Baby Gone(review)
halfWit
If I could, I'd title this "Freedom"(thing)
Roninspoon
Airline Hero(thing)
Ktistec
Why Women Are Always Cold(person)
doctor wilson
Drug policy reform(thing)
tejasa
Easy Raspberry Cheesecake(recipe)
Joysim
Drug policy reform(idea)
aneurin
Tyburn(place)
niruena
Boiling to death(idea)
artman2003
summer(thing)
doctor wilson
The Silver City and the Silent Sea(log)
Dreamvirus
The Silver City and the Silent Sea(poetry)
Aerobe
A nihilist's soulmate(poetry)
E2 is a by-product of the existence of The Everything Development Company