$Id: report-ike-interop0007.html,v 1.15 2000/07/28 08:46:10 sakane Exp $

The result of the round robin of IPsec/IKE
in the TAHI 2nd interoperability test

We held a small interoperability test of IPsec with IKE, which is one of the TAHI project's test events. It was held for 4 days from 14th July. You can get more detail of the event from http://www.tahi.org/inop/2ndinterop.html.

Here is the result of the round robin of the test. There is no meaning of the order of each implementations.
The description is the configuration only when IKE exchange was successful. All annotations are described at last part.

Implementaions

There were 11 implementations. 4 of them could talk IKE by IPv6. FW-1 and Windows2000 were for reference. Except them, a developer operated, improved and modified own implementation on the spot.
There was a additonal implementation, NetCocoon Analyzer which is a security protocol analyzer. We could take advantage of it to investigate some problem of exchange.

Default configuration

If no special declaration is described each cells in the result, below default configuration was used.

Notiation

N/A
the test was impossible because of mismatching address family, supported algorithm...
---
the test was not played.
###
same result when a implementation was responder of the session.
*
annotation which is described at last part.
X
empty.

Responder WS-ONE beta release Racoon current FW-1 v4.1 VP100 IX5000 alpha release IKED Windows2000 NetCocoon AR300V2 Sun IKE prototype MG1
Initiator Operator
WS-ONE beta release X
IPv6/IPv4
ESP
Tunnel/Transport mode
Phase1 rekeying ?(s)
Phase2 rekeying ?(s)
*9
ESP
Tunnel mode
---
IPv6
ESP
Transport mode
Phase1 rekeying ?(s)
Phase2 rekeying 100(s)
*1
---
ESP
Transport mode
*4
ESP
Tunnel mode
ESP
Transport mode
Phase1 rekeying 100(s)
Phase2 rekeying 300(s)
*10
ESP
Transport mode
Phase1 rekeying ?(s)
Phase2 rekeying ?(s)
IPv6
ESP
Tunnel mode
*16
kimura@comm.yamaha.co.jp
Racoon current ###
X
Pre-shared key/RSA Signature
ESP
Tunnel mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
*21
RSA Signature
ESP
Tunnel mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
*12
IPv6
ESP/AH+ESP
Transport mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
Pre-shared key/RSA Signature
Transport/Tunnel mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
*20
ESP
Transport mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
*6
ESP
Tunnel mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
*7,*22
ESP
Tunnel mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
ESP
Transport mode
Phase1 rekeying 500(s)
Phase2 rekeying 300(s)
*8
ESP/AH
Tunnel mode
*17
sakane@kame.net
FW-1 v1.4 ---
###
X
Pre-shared key/RSA Signature
ESP
Tunnel mode
Phase1 rekeying ???(s)
Phase2 rekeying ???(s)
*12
N/A
Main mode/Aggressive mode
Pre-shared key/RSA Signature
Tunnel mode
Phase1 rekeying ???(s)
Phase2 rekeying 1800(s)
ESP
Transport mode
ESP
Tunnel mode
ESP
Tunnel mode
---
---
sakane@ydc.co.jp
VP100 ---
###
###
X
N/A
Pre-shared key/RSA Signature
Tunnel mode
Phase1 rekeying ???(s)
Phase2 rekeying ???(s)
---
---
ESP
Tunnel mode
Phase1 rekeying 600(s)
Phase2 rekeying 600(s)
---
---
nanba@inf.furukawa.co.jp
IX5000 alpha release ###
###
N/A
N/A
X
N/A
N/A
N/A
N/A
N/A
---
natsuko@ipn.abk.nec.co.jp
IKED ---
###
###
###
N/A
X
ESP
Transport mode
ESP
Tunnel mode
Phase1 rekeying ???(s)
Phase2 rekeying ???(s)
ESP
Tunnel mode
Phase1 rekeying 100(s)
Phase2 rekeying 300(s)
ESP
Transport mode
Phase1 rekeying ???(s)
Phase2 rekeying ???(s)
---
y-watana@sdl.hitachi.co.jp
Windows2000 ---
*18
*18
*18
N/A
*18
X
???
---
---
---
kimura@comm.yamaha.co.jp
NetCocoon ---
###
###
###
N/A
###
###
X
---
###
---
fukuda@trc.mew.co.jp
AR300V2 ###
###
*14
###
N/A
###
###
###
X
*14
---
ichiro@allied-telesis.co.jp
Sun IKE prototype ###
*11
###
###
###
N/A
###
---
###
###
*5
X
---
sommerfeld@east.sun.com
MG-1 ###
###
---
---
---
---
---
###
---
---
X
K.Kawano@rdmg.mgcs.mei.co.jp

Annotation