Open source VPNs are available, but are totally unsupported by any
central responsible party.
FreeS/WAN is probably the leading product in this niche. It runs
under Linux. There is fairly detailed documentation that goes along
with it, and you can connect it with other IPSec solutions being
used elsewhere in the system. The IKE module uses RSA signatures or
shared keys only. (Remember, it was mentioned earlier that X.509
certs aren't being used much yet -- there's a bit of a chicken-and-egg situation
currently going on.)