Ipsec-tools

Jul 20, 2023

KAME racoon IKE daemon, ipsec-tools version

racoon speaks IKE ISAKMP/Oakley key management protocol, to establish security association with other hosts.

This is the IPSec-tools version of racoon.

Enchancements

  • Support of NAT-T and IKE fragmentation.
  • Support of many authentication algorithms.
  • Tons of bugfixes.

Known issues

  • Non-threaded implementation. Simultaneous key negotiation performance should be improved.
  • Cannot negotiate keys for per-socket policy.
  • Cryptic configuration syntax - blame IPsec specification too…
  • Needs more documentation.

Design choice, not a bug

  • racoon negotiate IPsec keys only. It does not negotiate policy. Policy must be configured into the kernel separately from racoon. If you want to support roaming clients, you may need to have a mechanism to put policy for the roaming client after phase 1 finishes.


Checkout these related ports:
  • Zzuf - Transparent application input fuzzer
  • Zlint - X.509 certificate linter
  • Zeronet - Decentralized websites using Bitcoin crypto and BitTorrent network
  • Zenmap - GUI frontend for the Nmap scanning utility
  • Zeek - System for detecting network intruders in real-time
  • Zaproxy - The OWASP zed attack proxy
  • Yubioath-desktop - GUI for displaying OATH codes with a Yubikey
  • Yubikey-personalization-gui - Graphical YubiKey personalization tool
  • Yubikey-manager-qt - Cross-platform application for configuring any YubiKey
  • Yubikey-agent - Seamless ssh-agent for YubiKeys
  • Yubico-piv-tool - Yubico PIV tool
  • Ylva - Command line password manager and file encryption program
  • Ykpers - Library and tool for personalization of Yubico's YubiKey
  • Ykclient - Yubico C client library
  • Yersinia - Layer 2 vulnerability scanner (switches, spanning tree, 802.1q ...)