Libreswan
A free IPsec and IKE VPN implementation for Linux, FreeBSD and macOS.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Libreswan
Libreswan implements IPsec with the Internet Key Exchange, supporting both IKEv1 and IKEv2. It descends from the FreeS/WAN project, which started in 1997. On Linux it uses the kernel's built-in XFRM IPsec stack, and it uses the NSS crypto library.
It ships with many Linux distributions, including Fedora, RHEL/EPEL and Arch Linux, so it can be installed with the usual package tools. Security fixes are released regularly, most recently 5.3.2. It suits administrators building standards-based site-to-site or remote-access VPNs.
Strengths
- Standards-based IPsec with IKEv1 and IKEv2
- Packaged in Fedora, RHEL/EPEL and Arch Linux
- Long history with active security maintenance
Limitations
- IPsec configuration has a steep learning curve
- No graphical interface
Details
- Pricing
- FreeFree software under GPLv2.
- License
- GPL-2.0
- Developer
- The Libreswan Project
- Platforms
- macOS, Linux, Command line
- How it runs
- Downloadable app
- Account
- Not required
- Best suited for
- Administrators setting up standards-based IPsec VPNs on Linux
- Categories
- VPN, Network tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to Libreswan
Compare allSoftware that can replace Libreswan for an important use case, and what changes if you switch.
strongSwan
An open-source IPsec VPN implementation using the IKEv2 and IKEv1 key exchange protocols.
strongSwan is another open-source IPsec implementation with a thorough IKEv2 stack, and adds Windows and Android support plus virtual IP pools via DHCP, RADIUS or SQL.
OpenVPN Community
The VPN protocol and client that has been the default for two decades, and still runs on everything.
OpenVPN Community replaces IPsec with its own protocol over TCP or UDP on any port, with clients on every major platform, though it is slower than WireGuard.
WireGuard
A small, fast VPN protocol and set of official clients that connect two machines by exchanging public keys.
WireGuard replaces IPsec and IKE with a small key-exchange-based protocol that is easier to audit, but each peer's tunnel address is set by hand.
SoftEther VPN
An open-source multi-protocol VPN server and client for remote access and site-to-site networking.
SoftEther VPN is a multi-protocol server and client with SSL-VPN, dynamic DNS and NAT traversal under Apache-2.0, and it also runs on Windows.
Algo VPN
Ansible scripts that stand up a personal WireGuard and IPsec VPN.
Algo VPN uses Ansible to deploy a personal WireGuard and IPsec server with fixed security defaults, avoiding manual IPsec configuration, but you pay for the cloud server.
Pritunl
A self-hosted VPN server for OpenVPN, WireGuard and IPsec, managed through a web interface.
Pritunl manages IPsec, OpenVPN and WireGuard from a web interface with site-to-site links, replacing hand-edited configuration files with a graphical interface.
Libreswan as an alternative
Listings that name Libreswan as an alternative.
ocserv
An open-source Linux SSL VPN server compatible with OpenConnect and AnyConnect clients.
Libreswan moves you to IPsec with IKEv1 and IKEv2, packaged in Fedora, RHEL and Arch, with a steep learning curve and no graphical interface.
Similar software
Related functionality, not necessarily a direct replacement.
IPFire
A hardened Linux-based firewall distribution with VPN support, network segmentation and a web management console.
OPNsense
An open-source firewall and routing platform based on FreeBSD that you install on your own hardware.
VyOS
An open-source network operating system that combines routing, firewall and VPN functions in one platform.
OpenConnect
An open-source command-line client for Cisco AnyConnect, GlobalProtect, Fortinet and other SSL VPNs.