I have a functioning VPN between a Linux/FreeSWAN firewall and a Cisco VPN3005 Concentrator. If anyone tries this particular combination, I found it necessary to add "pfs=no" to my ipsec.conf for the tunnel to the VPN3000. --Stafford