Libreswan

A free IPsec and IKE VPN implementation for Linux, FreeBSD and macOS.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About Libreswan

Libreswan implements IPsec with the Internet Key Exchange, supporting both IKEv1 and IKEv2. It descends from the FreeS/WAN project, which started in 1997. On Linux it uses the kernel's built-in XFRM IPsec stack, and it uses the NSS crypto library.

It ships with many Linux distributions, including Fedora, RHEL/EPEL and Arch Linux, so it can be installed with the usual package tools. Security fixes are released regularly, most recently 5.3.2. It suits administrators building standards-based site-to-site or remote-access VPNs.

Strengths

  • Standards-based IPsec with IKEv1 and IKEv2
  • Packaged in Fedora, RHEL/EPEL and Arch Linux
  • Long history with active security maintenance

Limitations

  • IPsec configuration has a steep learning curve
  • No graphical interface

Details

Pricing
FreeFree software under GPLv2.
License
GPL-2.0
Developer
The Libreswan Project
Platforms
macOS, Linux, Command line
How it runs
Downloadable app
Account
Not required
Best suited for
Administrators setting up standards-based IPsec VPNs on Linux
Categories
VPN, Network tools
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Alternatives to Libreswan

Compare all

Software that can replace Libreswan for an important use case, and what changes if you switch.

  • strongSwan

    An open-source IPsec VPN implementation using the IKEv2 and IKEv1 key exchange protocols.

    strongSwan is another open-source IPsec implementation with a thorough IKEv2 stack, and adds Windows and Android support plus virtual IP pools via DHCP, RADIUS or SQL.

  • OpenVPN Community

    The VPN protocol and client that has been the default for two decades, and still runs on everything.

    OpenVPN Community replaces IPsec with its own protocol over TCP or UDP on any port, with clients on every major platform, though it is slower than WireGuard.

  • WireGuard

    A small, fast VPN protocol and set of official clients that connect two machines by exchanging public keys.

    WireGuard replaces IPsec and IKE with a small key-exchange-based protocol that is easier to audit, but each peer's tunnel address is set by hand.

  • SoftEther VPN

    An open-source multi-protocol VPN server and client for remote access and site-to-site networking.

    SoftEther VPN is a multi-protocol server and client with SSL-VPN, dynamic DNS and NAT traversal under Apache-2.0, and it also runs on Windows.

  • Algo VPN

    Ansible scripts that stand up a personal WireGuard and IPsec VPN.

    Algo VPN uses Ansible to deploy a personal WireGuard and IPsec server with fixed security defaults, avoiding manual IPsec configuration, but you pay for the cloud server.

  • Pritunl

    A self-hosted VPN server for OpenVPN, WireGuard and IPsec, managed through a web interface.

    Pritunl manages IPsec, OpenVPN and WireGuard from a web interface with site-to-site links, replacing hand-edited configuration files with a graphical interface.

Libreswan as an alternative

Listings that name Libreswan as an alternative.

  • ocserv

    An open-source Linux SSL VPN server compatible with OpenConnect and AnyConnect clients.

    Libreswan moves you to IPsec with IKEv1 and IKEv2, packaged in Fedora, RHEL and Arch, with a steep learning curve and no graphical interface.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing