Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 10th August 2011, 09:54 AM
volant Offline
Registered User
 
Join Date: Aug 2011
Posts: 9
linuxfedorafirefox
Question Is ipsec same as ipsec-tools?

Dear Sir / Madam,

I have two fedora servers.
Server A
Server B

I cannot find ipsec.conf in my Server A.
I tried to yum install ipsec-tools, I can install.
I tried to yum install ipsec, it says ipsec not found.

I wonder is ipsec same as ipsec-tools?
From google, it always guide user how to install ipsec-tools, but not ipsec.
Where can I get the ipsec if it is the pre-requisites of ipsec-tools?
Reply With Quote
  #2  
Old 10th August 2011, 03:44 PM
DBelton's Avatar
DBelton Offline
Administrator
 
Join Date: Aug 2009
Posts: 6,613
linuxfirefox
Re: Is ipsec same as ipsec-tools?

try installing openswan and ipsec-tools.

openswan is the ipsec package.

Code:
[Me@tower11 ~]$ yum info openswan
Loaded plugins: langpacks, presto, refresh-packagekit
Installed Packages
Name        : openswan
Arch        : i686
Version     : 2.6.33
Release     : 1.fc15
Size        : 2.4 M
Repo        : installed
From repo   : updates-testing
Summary     : IPSEC implementation with IKEv1 and IKEv2 keying protocols
URL         : http://www.openswan.org/
License     : GPLv2+
Description : Openswan is a free implementation of IPsec & IKE for Linux.  IPsec
            : is the Internet Protocol Security and uses strong cryptography to
            : provide both authentication and encryption services.  These
            : services allow you to build secure tunnels through untrusted
            : networks.  Everything passing through the untrusted net is
            : encrypted by the ipsec gateway machine and decrypted by the
            : gateway at the other end of the tunnel.  The resulting tunnel is a
            : virtual private network or VPN.
            : 
            : This package contains the daemons and userland tools for setting
            : up Openswan. It supports the NETKEY/XFRM IPsec kernel stack that
            : exists in the default Linux kernel.
            : 
            : Openswan 2.6.x also supports IKEv2 (RFC4306)
the linux kernel now also has a native ipsec stack. (not sure if Fedora compiles it's kernels to support the ipsec features, though. They probably do)

Last edited by DBelton; 10th August 2011 at 03:56 PM.
Reply With Quote
  #3  
Old 10th August 2011, 04:25 PM
volant Offline
Registered User
 
Join Date: Aug 2011
Posts: 9
linuxfedorafirefox
Re: Is ipsec same as ipsec-tools?

Dear Sir,
Thank you for your response!
The openswan and ipsec-tools already installed on my server.

I should explain in further.
Server A - fedora 8
Server B - fedora 13

I did not install anything on f13, the ipsec service exists by default.
The ipsec.conf located in /etc/ipsec.conf
I type command: ipsec, it returns the following:
Usage: ipsec command argument ...
Use --help for list of commands, or see ipsec(8) manual page
or the Openswan documentation for names of the common ones.
Most have their own manual pages, e.g. ipsec_auto(8).
See <http://www.openswan.org> for more general info.


there is no ipsec.conf in /etc/ in my f8.
When i type command 'ipsec', it says:
[root@server]# ipsec
bash: ipsec: command not found


Anyway, i can see the ipsec service in f8 and i have enabled it.
Does it means my IPSEC is working fine in f8 as well?
Reply With Quote
  #4  
Old 10th August 2011, 04:49 PM
stevea's Avatar
stevea Offline
Registered User
 
Join Date: Apr 2006
Location: Ohio, USA
Posts: 8,298
linuxfedorafirefox
Re: Is ipsec same as ipsec-tools?

Not sure you really want or need to run openswan anymore - tho' I'm no expert on the topic.

It appears that the primary functionality is to act as a key service. Sort of like the NetworkManager wifi supplicant. It seems to be old and poorly supported, and not generally needed if you just have a few keys to manage.

The ONLY kernel switches for IPsec are
CONFIG_INET_AH=m
CONFIG_INET_ESP=m
CONFIG_INET_IPCOMP=m
CONFIG_INET_XFRM_TUNNEL=m
CONFIG_INET_TUNNEL=m
CONFIG_INET_XFRM_MODE_TRANSPORT=m
CONFIG_INET_XFRM_MODE_TUNNEL=m
CONFIG_INET_XFRM_MODE_BEET=m
Crypto, hashes and tunnel code,
and fedora, as indicated above makes all these as modules.
ah4.ko, esp4.ko ....
__________________
None are more hopelessly enslaved than those who falsely believe they are free.
Johann Wolfgang von Goethe
Reply With Quote
Reply

Tags
ipsec, ipsectools

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
ipsec-tools missing IPsec tab packeto Installation and Live Media 1 5th August 2011 07:44 AM
ipsec-tools update rpm for 0.6.7? R-R Security and Privacy 5 16th August 2007 09:24 PM
[SECURITY] Fedora Core 2 Update: ipsec-tools-0.2.5-2 ewdi Advisories & Updates 0 28th May 2004 07:01 PM


Current GMT-time: 21:07 (Saturday, 18-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat