Release of OpenIKED 7.2, a portable implementation of the IKEv2 protocol for IPsec.

The OpenBSD project has released OpenIKED 7.2, an implementation of the IKEv2 protocol developed by the OpenBSD project. This is the fourth release of OpenIKED as a separate project — initially, the IKEv2 components were an inseparable part of the OpenBSD IPsec stack, but they were later separated into a stand-alone portable package and can now be used on other operating systems. OpenIKED has been tested on FreeBSD, NetBSD, macOS, and various Linux distributions including Arch, Debian, Fedora, and Ubuntu. The code is written in C and is released under the ISC license.

OpenIKED allows for the deployment of virtual private networks based on IPsec. The IPsec stack consists of two main protocols: the key exchange protocol (IKE) and the protocol for transmitting encrypted traffic (ESP). OpenIKED implements authentication, configuration, key exchange, and security policy maintenance elements, while the traffic encryption protocol ESP is typically provided by the operating system's kernel. OpenIKED supports several authentication methods, including pre-shared keys, EAP MSCHAPv2 with X.509 certificates, and RSA and ECDSA public keys.

In the new version:

  • Counters have been added with statistics for the background process iked, which can be viewed with the command ‘ikectl show stats.’
  • It is now possible to send certificate chains in multiple CERT payloads.
  • To improve compatibility with older versions, a payload with a vendor identifier has been added.
  • Rule searching has been enhanced considering the srcnat property.
  • NAT-T functionality has been established in Linux.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster