IPsec/IKEv2-based VPN software for Linux
| Proposal No. | ENCR | PRF | INTEG | DH |
| 1 | 3DES | HMAC_SHA2_512 | HMAC_SHA2_512_256 | Group14(MODP2048) |
| AES_CBC_256 | HMAC_SHA2_384 | HMAC_SHA2_384_192 | Group5(MODP1536) | |
| AES_CBC_192 | HMAC_SHA2_256 | HMAC_SHA2_256_128 | Group2(MODP1024) | |
| AES_CBC_128 | HMAC_SHA1 | HMAC_SHA1_96 | ||
| HMAC_MD5 | HMAC_MD5_96 |
| Proposal No. | ENCR | INTEG | ESN |
| 1 | 3DES | HMAC_SHA2_512_256 | Enabled. |
| AES_CBC_256 | HMAC_SHA2_384_192 | Disabled. | |
| AES_CBC_192 | HMAC_SHA2_256_128 | ||
| AES_CBC_128 | HMAC_SHA1_96 | ||
| HMAC_MD5_96 |
| Side | Protocol | Port range | Address range |
| Initiator (TSi) | Any(0) | Any(0 -- 65535) | Any(IPv4: 0.0.0.0 - 255.255.255.255) |
| Initiator (TSi) | Any(0) | Any(0 -- 65535) | Any(IPv6: :: - ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff) |
| Responder (TSr) | Any(0) | Any(0 -- 65535) | Any(IPv4: 0.0.0.0 - 255.255.255.255) |
| Responder (TSr) | Any(0) | Any(0 -- 65535) | Any(IPv6: :: - ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff) |
| Attribute |
Supported by initiator (Remote access client) |
Supported by responder (Remote configuration server) |
|
INTERNAL_IP4_ADDRESS (VPN interface's address) |
Yes. | Yes. |
|
INTERNAL_IP4_NETMASK (VPN interface's netmask) |
Yes. | Yes. |
|
INTERNAL_IP4_SUBNET (Split tunneling, internal routing entries) |
Yes. | Yes. |
|
INTERNAL_IP4_DNS (DNS Server) |
Yes. | Yes. |
|
INTERNAL_IP4_NBNS (WINS Server) |
No. | Yes. |
| INTERNAL_IP4_DHCP | No. | No. |
| APPLICATION_VERSION | Yes. | Yes. |
|
INTERNAL_IP6_ADDRESS (VPN interface's address and netmask) |
Yes. | Yes. |
|
INTERNAL_IP6_DNS (DNS Server) |
Yes. | Yes. |
|
INTERNAL_IP6_SUBNET (Split tunneling, internal routing entries) |
Yes. | Yes. |
|
INTERNAL_IP6_NBNS (WINS Server) |
No. | Yes. |
| INTERNAL_IP6_DHCP | No. | No. |
|
RHP_IPV4_GATEWAY (28468, a default gateway for bridge config) |
Yes. | Yes. |
|
RHP_IPV6_GATEWAY (28469, a default gateway for bridge config) |
Yes. | Yes. |
|
RHP_DNS_SFX (28467, a FQDN's suffix for split DNS) |
Yes. | Yes. |
|
RHP_IPV6_AUTOCONF (28470, IPv6 address Auto-configuration over IPsec) |
Yes. | Yes. |