VPNC logo
VPNC members | VPN technologies | Mailing list | Join VPNC
Interoperability testing | Documentation profiles
VPN standards | IPsec archives | Features chart | VPN white papers
VPN conferences | IPsec bakeoff | Definitions | HIPAA | VPNC home

VPNC Basic Conformance Test

VPNC conformance logo

The Basic Conformance test is to see whether or not the tested gateway acts as a gateway for very basic IPsec operations. To pass, a host on a network behind the test gateway must reach a web server on a nework behind the conformance gateway.

There are two conformance gateways that are tested against: one running OpenBSD, the other running KAME. These two systems were chosen because the are independently-developed, have open source code, are actively maintained, and have been widely tested against commercial systems by their developers.

When testing, the test gateway initiated and set up a Phase 1 with the conformance gateway and a phase 2 for the host on the networks behind each gateway. In IKE Main Mode, the test gateway proposed TripleDES, SHA-1, MODP group 2 (1024-bit), a pre-shared secret of "mekmitasdigoat", no PFS, and no rekeying. After setting up phase 1 and phase 2, the host behind the test gateway went to the web server on the host behind the conformance gateway and got a short message there. The test was then repeated on the second conformance gateway.

The following lists the products that passed. The links after the product names are to the debugging information generated on each conformance gateway during the successful test. It is unlikely that this information is of much value to typical users; however, without it, you have no proof that the company even tested their products against the conformance gateways. On each conformance gateway, the debug output is:

CompanyProductOpenBSD testingKAME testing
ADTRANNetVanta 2000 debug, report, outside, inside debug, outside, inside
Ashley LaurentBroadWay ISS debug, report, outside, inside debug, outside, inside
Backbone Security.comRibcage debug, report, outside, inside debug, outside, inside
Check Point SoftwareVPN-1 Gateway debug, report, outside, inside debug, outside, inside
CiscoIOS IPsec debug, report, outside, inside debug, outside, inside
CiscoVPN 3000 Concentrator debug, report, outside, inside debug, outside, inside
CryptekDiamondTEK debug, report, outside, inside debug, outside, inside
CyberGuardPremium Appliance Firewall family debug, report, outside, inside debug, outside, inside
DigiSAFEBigBouncer debug, report, outside, inside debug, outside, inside
DigiSAFENetProtect debug, report, outside, inside debug, outside, inside
Encore NetworksBANDIT family debug, report, outside, inside debug, outside, inside
Enterasys NetworksAurorean Virtual Network debug, report, outside, inside debug, outside, inside
Enterasys NetworksXSR Security Router family debug, report, outside, inside debug, outside, inside
eSoftInstaGate debug, report, outside, inside debug, outside, inside
HifnIPSECure debug, report, outside, inside debug, outside, inside
IntotoiGateway family debug, report, outside, inside debug, outside, inside
MicrosoftWindows 2000 SP1 debug, report, outside, inside debug, outside, inside
NETGEARFVL328 debug, report, outside, inside debug, outside, inside
NETGEARFVS318 debug, report, outside, inside debug, outside, inside
NetKlassNetKlass SME100 debug, report, outside, inside debug, outside, inside
NetScreenNetScreen debug, report, outside, inside debug, outside, inside
NokiaNokia VPN debug, report, outside, inside debug, outside, inside
Nortel NetworksContivity debug, report, outside, inside debug, outside, inside
Quarry TechnologiesiQ-series Switches debug, report, outside, inside debug, outside, inside
SafeNetSafeNet debug, report, outside, inside debug, outside, inside
SafeNetHighAssurance 2000 Gateway debug, report, outside, inside debug, outside, inside
SnapGearSnapGear debug, report, outside, inside debug, outside, inside
SSH Communications SecurityIPSEC Express debug, report, outside, inside debug, outside, inside
SSH Communications SecurityQuickSec Toolkit debug, report, outside, inside debug, outside, inside
SSH Communications SecuritySSH Sentinel debug, report, outside, inside debug, outside, inside
StonesoftStoneGate debug, report, outside, inside debug, outside, inside
WatchGuardWatchGuard Firebox Vclass debug, report, outside, inside debug, outside, inside
Wipro TechnologiesWipro Home Gateway debug, report, outside, inside debug, outside, inside

If you have comments or questions about VPNC's testing, please feel free to send them to Paul Hoffman, VPNC's director, at paul.hoffman@vpnc.org.