24. Security

ApplicationPackageVersionWorked ByURLsCommentStatus
Virtual Private Networks
Linux 2.6
Linux 2.6AllMaintainers 
                                    Source code
                                  Linux 2.6 includes a robust IPv6-enabled IPSEC stack derived from the USAGI Project IPSEC stack. 
                                    Native support
FreeBSD
FreeBSD4.0 and beyondMaintainers 
                                    Source code
                                  FreeBSD includes a robust IPv6-enabled IPSEC stack derived from the KAME Project IPSEC stack since version 4.0. 
                                    Native support
OpenBSD
OpenBSD2.7 and beyondMaintainers 
                                    Source code
                                  OpenBSD includes a robust IPv6-enabled IPSEC stack derived from the KAME Project IPSEC stack since version 2.7. 
                                    Native support
NetBSD
NetBSD1.5 and beyondMaintainers 
                                    Source code
                                  NetBSD includes a robust IPv6-enabled IPSEC stack derived from the KAME Project IPSEC stack since version 1.5. 
                                    Native support
yavipin
yavipin0.9.6Maintainers 
                                    Source code
                                  Yavipind is a secure tunnel aka 2 peers securely forwarding packets toward each other. It forwards any kind of packet (IPv4, IPv6 or other) sent over the virtual point-to-point device (e.g. tun0). It fully runs in linux userspace. 
                                    Native support
openvpn
openvpn1.6.0Maintainers 
                                    Source code
                                  OpenVPN is an easy-to-use, robust, and highly configurable SSL VPN daemon which can be used to securely link two or more private networks using an encrypted tunnel over the internet. 
                                    Native support
freeswan
freeswan2.06Maintainers 
                                    Source code
                                  Linux FreeS/WAN is an implementation of IPSEC and IKE for the Linux operating system. The project's primary objective is to help make IPSEC widespread by providing source code which is freely available, runs on a range of machines including ubiquitous cheap PCs, and is not subject to the US or other nations' export restrictions. At the moment, it seems that this project is no longer maintained and that IPv6 support code in freeswan is still experimental, as the configuration scripts do not support IPv6 yet and the environment setup must be done via low-level tools. 
                                    Native support
openswan
openswan2.2.0dr1Maintainers 
                                    Source code
                                  Openswan is an Open Source implementation of IPsec for the Linux operating system. Is it a code fork of the FreeS/WAN project, started by a few of the developers who were growing frustrated with the politics surrounding the FreeS/WAN project. At the moment, it seems that IPv6 support code in openswan is still experimental, as the configuration scripts do not support IPv6 yet and the environment setup must be done via low-level tools. 
                                    Native support
strongswan
strongswan4.1.9Maintainers 
                                    Source code
                                  strongSwan is an OpenSource IPsec implementation for the Linux operating system. It is based on the discontinued FreeS/WAN project and the X.509 patch which we developped over the last three years. The focus is on simplicity of configuration, strong encryption and authentication methods, and powerful IPsec policies supporting large and complex VPN networks. IPv6 host-to-host, net-to-net and roadwarrior IPsec tunnel configurations have now been fully tested and documented in IKEv1 and IKEv2 scenarios. Also supports full interaction of established IPsec tunnels with ip6tables firewall rules via an extended _updown script. 
                                    Native support
Security Auditing
Nmap
Nmap3.50Maintainers 
                                    Source code
                                  Nmap ("Network Mapper") is an open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (ports) they are offering, what operating system (and OS version) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. Nmap features IPv6 support since release 3.10ALPHA1. 
                                    Native support
halfscan6
halfscan60.2Maintainers 
                                    Source code
                                  A simple TCP/IPv6 port scanner. 
                                    Native support
nessus
nessus2.0.7Maintainers 
                                    Source code
                                  The Nessus Project aims to provide to the internet community a free, powerful, up-to-date and easy to use remote security scanner. A security scanner is a software which will audit remotely a given network and determine whether bad guys (aka 'crackers') may break into it, or misuse it in some way. Nessus is very fast, reliable and has a modular architecture that allows you to fit it to your needs. Unfortunately, not only Nessus does not have IPv6 support, but at the moment the developers have also no plans to add it. 
                                    Not working
Packet Sniffers
tcpdump
tcpdump3.7.2Maintainers 
                                    Source code
                                  Tcpdump is the most famous tool for network monitoring and data acquisition. This software was originally developed by the Network Research Group at the Lawrence Berkeley National Laboratory. Tcpdump uses libpcap, a system-independent interface for user-level packet capture. Before building tcpdump, you must first retrieve and build libpcap. 
                                    Native support
libpcap
libpcap0.7.2Maintainers 
                                    Source code
                                  libpcap is a system-independent interface for user-level packet capture that provides a portable framework for low-level network monitoring. Applications include network statistics collection, security monitoring, network debugging, etc. 
                                    Native support
ethereal
ethereal0.9.13Maintainers 
                                    Source code
                                  Ethereal is a free network protocol analyzer for Unix and Windows. It allows you to examine data from a live network or from a capture file on disk. You can interactively browse the capture data, viewing summary and detail information for each packet. Ethereal has several powerful features, including a rich display filter language and the ability to view the reconstructed stream of a TCP session. 
                                    Native support
COLD
COLD1.0.14alphaMaintainers 
                                    Source code
                                  COLD is both a network anaylsis tool and a protocol analyzer. It is distributed freely, so its usage is free and the package is freely available. COLD is a network monitoring and protocol analyzing tool which allows to study, maintain and troubleshoot networks by extracting flowing data and printing out the contents and structure. COLD has been developed for troubleshooting, educational, security and commercial purposes only. 
                                    Native support
ndpmon
ndpmon0.1bMaintainers 
                                    Source code
                                  NDPMon, Neighbor Discovery Protocol Monitor, is a tool working with ICMPv6 packets. NDPMon observes the local network to see if nodes using neighbor discovery messages behave properly. When it detects a suspicious Neighbor Discovery message, it notifies the administrator by writing in the syslog and in some cases by sending an email report. NDPMon is an equivalent of ArpWatch for IPv6. 
                                    Native support
Packet Forgers
Raw Socket Library
libsockN/AMaintainers 
                                    Source code
                                  Raw Socket Library provides a simple mechanism to send raw socket packet using IPV4 and IPV6 using a simple struct. It currently supports TCP, ICMP, UDP, and ICMPv6. 
                                    Native support
Updated 09.07.2008Documentation | DeepSpace6