strongSwan

An open-source IPsec VPN implementation using the IKEv2 and IKEv1 key exchange protocols.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

1 more ways to get strongSwan

Package managers

About strongSwan

strongSwan implements the Internet Key Exchange protocols to secure IP traffic with IPsec. It handles both policy-based and route-based setups, from a single road-warrior tunnel to complex gateway configurations. Supported features include IPv6 tunnel and transport mode, MOBIKE for changing addresses, NAT traversal, IKEv2 message fragmentation and dead peer detection. Virtual IP pools can be managed by the daemon, DHCP, RADIUS or an SQL database.

It runs on Linux, Android, FreeBSD, macOS and Windows. Version 6.1.0 was released in September 2026. The code is under GPLv2, and commercial licences are also offered.

Strengths

  • Thorough IKEv2 implementation with many IETF extensions
  • Runs on Linux, Android, FreeBSD, macOS and Windows
  • Flexible virtual IP pools through DHCP, RADIUS or SQL
  • Actively maintained with recent releases

Limitations

  • Configuration requires solid IPsec knowledge
  • Mainly configured through files and the command line

Details

Pricing
FreeFree under GPLv2, with commercial licensing available as an option.
License
GPL-2.0
Developer
The strongSwan contributors
Platforms
Windows, macOS, Linux, Android, Self-hosted, Command line
How it runs
Downloadable app, Self-hosted
Account
Not required
Best suited for
Administrators building standards-based IPsec VPN gateways and clients
Categories
VPN, Network tools
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Alternatives to strongSwan

Compare all

Software that can replace strongSwan for an important use case, and what changes if you switch.

  • Libreswan

    A free IPsec and IKE VPN implementation for Linux, FreeBSD and macOS.

    Libreswan is another GPL-2.0 IPsec implementation with IKEv1 and IKEv2, packaged in Fedora, RHEL and Arch, but it does not run on Windows or Android.

  • SoftEther VPN

    An open-source multi-protocol VPN server and client for remote access and site-to-site networking.

    SoftEther VPN is a multi-protocol server and client with an SSL-VPN that passes restrictive firewalls, under Apache-2.0, with many options to learn.

  • OpenVPN Community

    The VPN protocol and client that has been the default for two decades, and still runs on everything.

    OpenVPN Community replaces IPsec with an SSL-based protocol that runs over TCP or UDP on any port, with clients on every major platform.

  • WireGuard

    A small, fast VPN protocol and set of official clients that connect two machines by exchanging public keys.

    WireGuard swaps IKE negotiation for simple public-key exchange in a small, auditable protocol, but it is not a standards-based IPsec implementation.

  • Pritunl

    A self-hosted VPN server for OpenVPN, WireGuard and IPsec, managed through a web interface.

    Pritunl manages IPsec, OpenVPN and WireGuard servers from one web interface, replacing strongSwan's file and command-line configuration.

strongSwan as an alternative

Listings that name strongSwan as an alternative.

  • Algo VPN

    Ansible scripts that stand up a personal WireGuard and IPsec VPN.

    strongSwan provides a full IKEv2 IPsec implementation across Linux, Android, macOS and Windows, but configuration requires solid IPsec knowledge and it has no WireGuard.

  • ocserv

    An open-source Linux SSL VPN server compatible with OpenConnect and AnyConnect clients.

    strongSwan switches to standards-based IPsec with IKEv2 and flexible virtual IP pools, running on Linux, Android, FreeBSD, macOS and Windows, configured through files.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing