Linux FreeS/WAN and Checkpoint Firewall1
Jsutin asks: "Does anyone have a working FreeS/WAN implementation talking to Checkpoint Firewall1? I've searched through a lot of Linux archives, FreeS/WAN archives, sent people email, and last but not least asked God to help me. And unfortunately all has fallen through! I've run across a few threads here and there that say it can be done but no documents explaining how to do it. I'm trying to push Linux as a VPN gateway for remote offices and would be greatly appreciative if anyone reading this has any suggestions?"
"
Getting FreeS/WAN and Firewall-1 shouldnt be to hard... I wasnt aware of the FreeS/WAN project (until now :) , but now i cant want to set it up and test it with Linux! (the coolest advantage of working at a Checkpoint reseller, lots of Nokia based Checkpoint firewall-1 boxes laying around) ;)
Ill install S/WAN on some redhat boxes here and test it with checkpoint 4.0 and 4.1... (and hopefully Checkpoint Linux someday soon
- Cybie! aka Ralph Bonnell
Cybie! aka Ralph Bonnell
How about getting Free S/WAN working with the new PICS firewall/ipsec machines?
-- rage, rage against the dying of the light
I hunted through the mail-list archive and found the following:
- The Question. More or less content-free.
- Some info, some questions.
- Some answers to the above questions. Like, FreeSwan no longer supports plain DES; you have to use 3DES. And, "Manual-key setup has to be done on *both* ends"
- This guy is willing to pay for help.
- Assload of debugging data, from Interop setup.
Looking other places (Google, Yahoo, etc), I found this:Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
... that makes up for Checkpoint's incorrect and incomplete, and sometimes non-existant, documentation: Checkpoint Quick Reference, provided by some guy named "joe".
Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
Here is a VPN Pointer Page that has a IPSec config files for FW-1 & FreeS/WAN Haven't had a chance to test it yet, but I too am very keen to see this work, seeing as we're implmenting FW-1 here & I want to roll out S/WAN Internationally...