1<!DOCTYPE html> 2<html lang="en"> 3 <head> 4 <meta charset="utf-8"> 5 <meta http-equiv="X-UA-Compatible" content="IE=edge"> 6 <meta name="viewport" content="width=device-width, initial-scale=1"> 7 <title>strongSwan - IPsec VPN for Linux, Android, FreeBSD, macOS, Windows</title> 8 <meta name="author" content="strongSwan project"> 9 <meta name="description" content="strongSwan is an open-source, modular and portable IPsec-based VPN solution"> 10 <meta property="og:image" content="https://www.strongswan.org/images/strongswan_square_large.png" /> 11 <meta property="og:image:width" content="800" /> 12 <meta property="og:image:height" content="800" /> 13 <link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png"> 14 <link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png"> 15 <link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png"> 16 <link rel="manifest" href="/site.webmanifest"> 17 <link rel="mask-icon" href="/safari-pinned-tab.svg" color="#d70f37"> 18 <meta name="msapplication-TileColor" content="#ffffff"> 19 <meta name="theme-color" content="#ffffff"> 20 <link rel="stylesheet" href="/css/style.css"> 21 <link rel="stylesheet" href="/css/fa/css/fontawesome.min.css"> 22 <link rel="stylesheet" href="/css/fa/css/brands.min.css"> 23 <link rel="stylesheet" href="/css/fa/css/solid.min.css"> 24 25 <base target="_top"> 26 </head> 27 <body class="has-navbar-fixed-top"> 28 <nav class="navbar is-fixed-top" role="navigation" aria-label="main navigation"> 29 <div class="container"> 30 <div class="navbar-brand"> 31 <a class="navbar-item" href="/"> 32 <img src="/images/logo.svg" alt="strongSwan Logo" width="170"> 33 </a> 34 <a role="button" class="navbar-burger" aria-label="menu" aria-expanded="false" data-target="navbarBasicExample"> 35 <span aria-hidden="true"></span> 36 <span aria-hidden="true"></span> 37 <span aria-hidden="true"></span> 38 </a> 39 </div> 40 41 <div id="mainNav" class="navbar-menu"> 42 <div class="navbar-start"> 43 </div> 44 45 <div class="navbar-end"> 46 <a class="navbar-item" href="/documentation.html"> 47 Documentation 48 </a> 49 <a class="navbar-item" href="/support.html"> 50 Support 51 </a> 52 <a class="navbar-item" href="/license.html"> 53 License 54 </a> 55 <a class="navbar-item" href="/about.html"> 56 About 57 </a> 58 <div class="navbar-item"> 59 <div class="buttons"> 60 <a class="button is-primary is-inverted is-rounded" href="/blog/"> 61 <strong>Blog</strong> 62 </a> 63 <a class="button is-primary is-rounded" href="/download.html"> 64 <strong>Download</strong> 65 </a> 66 <a class="button is-light is-rounded" href="https://github.com/strongswan"> 67 <span class="icon-text"> 68 <span class="icon"> 69 <i class="fa-brands fa-github"></i> 70 </span> 71 <span><strong>GitHub</strong></span> 72 </span> 73 </a> 74 </div> 75 </div> 76 </div> 77 </div> 78 </div> 79 </nav> 80<section class="hero is-medium" style="background-image: url('/images/bg-1.svg'); background-repeat: no-repeat; background-position: top right; background-size: 100vw auto;"> 81<div class="hero-body"> 82<div class="container"> 83<div class="columns"> 84<div class="column is-align-self-center"> 85<h1 class="title">strongSwan</h1> 86<h2 class="subtitle">Open-source, modular and portable IPsec-based VPN solution</h2> 87</div> 88<div class="column is-one-third"> 89<div class="panel is-primary"> 90<p class="panel-heading">Latest Release</p> 91<a class="panel-block is-active has-background-white-def" href="/download.html"> 92 <span class="panel-icon"> <i class="fas fa-download" aria-hidden="true"><!--i--></i> </span> 93 <strong>Version 6.1.0</strong>, 2026-09-07 94</a> 95<a class="panel-block has-background-white-def" href="https://github.com/strongswan/strongswan/releases/tag/6.1.0"> 96 <span class="panel-icon"> <i class="fas fa-book" aria-hidden="true"><!--i--></i> </span> 97 Changelog 98</a> 99<p class="panel-footer has-background-white-def has-text-centered">Get the latest open-source GPLv2 version now, or learn more about <strong>
99<a href="/license.html">commercial licensing</a></strong> options</p> 100</div> 101</div> 102</div> 103</div> 104</div> 105</section> 106<section class="hero is-medium is-black"> 107<div class="hero-body"> 108<div class="container"> 109<h3 class="title">strongSwan is a comprehensive implementation of the <strong class="has-text-primary">Internet Key Exchange</strong> (IKE) protocols that allows securing IP traffic in policy- and route-based <strong class="has-text-primary">IPsec</strong> scenarios from simple to very complex.</h3> 110<p><a class="button is-black is-outlined is-inverted is-uppercase is-small p-4" href="#features">More about its features</a></p> 111</div> 112</div> 113</section> 114<section class="section features"> 115<div class="container content"> 116<h3 class="title" id="features">Features</h3> 117<p class="mb-5">Below you'll find some of the key features of strongSwan. More information and how-tos can be found in <a href="/documentation.html">the documentation</a>.</p> 118<div class="tile is-ancestor"> 119<div class="tile is-parent is-vertical"> 120<div class="tile is-child box is-light is-flex is-flex-direction-column"> 121<h4>Internet Key Exchange (IKE)</h4> 122<ul> 123<li>Implements the IKEv2 (<a href="https://www.rfc-editor.org/rfc/rfc7296.html">RFC 7296</a>) key exchange protocol (IKEv1 is also supported)</li> 124<li>Fully tested support of <a href="https://docs.strongswan.org/docs/latest/config/IPv6.html">IPv6</a> IPsec tunnel and transport mode connections</li> 125<li>Dynamic IP address and interface update with MOBIKE (<a href="https://www.rfc-editor.org/rfc/rfc4555.html">RFC 4555</a>)</li> 126<li>Automatic insertion and deletion of IPsec-policy-based firewall rules</li> 127<li>NAT-Traversal via UDP encapsulation and port floating (<a href="https://www.rfc-editor.org/rfc/rfc3947.html">RFC 3947</a>)</li> 128<li>Support of IKEv2 message fragmentation (<a href="https://www.rfc-editor.org/rfc/rfc7383.html">RFC 7383</a>) to avoid issues with IP fragmentation</li> 129<li>Dead Peer Detection (DPD, <a href="https://www.rfc-editor.org/rfc/rfc3706.html">RFC 3706</a>) takes care of dangling tunnels</li> 130<li>Virtual IP address pool managed by IKE daemon, DHCP, RADIUS or SQL database</li> 131<li>IKEv2 SAs may be redirected to another gateway (<a href="https://datatracker.ietf.org/doc/html/rfc5685">RFC 5685</a>)</li> 132<li>Childless IKEv2 SA initiation is supported (<a href="https://datatracker.ietf.org/doc/html/rfc6023">RFC 6023</a>)</li> 133<li><a href="https://docs.strongswan.org/docs/latest/features/ietf.html">Implemented RFCs and Internet Drafts</a></li> 134</ul> 135</div> 136<div class="tile is-child box is-flex is-flex-direction-column"> 137<h4>Modularity</h4> 138<ul> 139<li>A modular plugin system offers great extensibility and flexibility</li> 140<li>Plugins can provide crypto algorithms, credentials, authentication methods, configs, access to IPsec and network stacks and more</li> 141<li>Optional built-in integrity and crypto tests for plugins and libraries</li> 142</ul> 143</div> 144</div> 145<div class="tile is-parent is-vertical"> 146<div class="tile is-child box is-light is-flex is-flex-direction-column"> 147<h4>Authentication / Cryptography</h4> 148<ul> 149<li>Secure IKEv2 EAP user authentication (EAP-SIM, EAP-AKA, EAP-TLS, EAP-TTLS, EAP-PEAP, EAP-MSCHAPv2, etc.)</li> 150<li>Optional relaying of EAP messages to AAA server via EAP-RADIUS plugin</li> 151<li>Support of IKEv2 Multiple Authentication Exchanges (<a href="https://www.rfc-editor.org/rfc/rfc4739.html">RFC 4739</a>)</li> 152<li>Authentication based on X.509 certificates or pre-shared keys</li> 153<li>Use of strong signature algorithms with Signature Authentication in IKEv2 (<a href="https://www.rfc-editor.org/rfc/rfc7427.html">RFC 7427</a>)</li> 154<li>Support for CRLs and OCSP (<a href="https://www.rfc-editor.org/rfc/rfc6960.html">RFC 6960</a>)</li> 155<li>Storage of private keys and certificates on a smartcard (PKCS #11 interface) or protected by a TPM 2.0</li> 156<li>Support of NIST elliptic curve DH groups and ECDSA signatures and certificates</li> 157<li>Support of X25519 elliptic curve DH group (<a href="https://www.rfc-editor.org/rfc/rfc8031.html">RFC 8031</a>) and Ed25519 signatures and certificates (<a href="https://www.rfc-editor.org/rfc/rfc8420.html">RFC 8420</a>)</li> 158<li>Support for multiple classic and post-quantum key exchanges (<a href="https://datatracker.ietf.org/doc/html/rfc9370">RFC 9370</a>), including ML-KEM (FIPS 203)</li> 159<li>Trusted Network Connect compliant to PB-TNC (<a href="https://www.rfc-editor.org/rfc/rfc5793.html">RFC 5793</a>), PA-TNC (<a href="https://www.rfc-editor.org/rfc/rfc5792.html">RFC 5792</a>), PT-TLS (<a href="https://www.rfc-editor.org/rfc/rfc6876.html">RFC 6876</a>), PT-EAP (<a href="https://www.rfc-editor.org/rfc/rfc7171.html">RFC 7171</a>) and SWIMA for PA-TNC (<a href="https://www.rfc-editor.org/rfc/rfc8412.html">RFC 8412</a>)</li> 160</ul> 161</div> 162<div class="tile is-child box is-flex is-flex-direction-column"> 163<h4>Portability</h4> 164<ul> 165<li>Runs on Linux 2.6, 3.x, 4.x, 5.x and 6.x kernels</li> 166<li>Has been ported to Android, FreeBSD, macOS, iOS and Windows</li> 167<li>Integration into Linux desktops via <a href="/download.html#networkmanager">NetworkManager plugin</a></li> 168<li>An <a href="/download.html#android">Android app</a> is available</li> 169</ul> 170</div> 171</div> 172</div> 173</div> 174</section> 175<section class="hero is-medium is-black"> 176<div class="hero-body"> 177<div class="container"> 178<h3 class="title">The strongSwan source code is licensed under the <strong class="has-text-primary">GPLv2</strong> with <strong class="has-text-primary">commercial licensing</strong> options available</h3> 179<p><a class="button is-black is-outlined is-inverted is-uppercase is-small p-4" href="/lice
179nse.html">More about commercial licensing</a></p> 180</div> 181</div> 182</section> 183<section class="section features"> 184<div class="container content"> 185<h3 class="title" id="features">Documentation and Support</h3> 186<p><a class="button is-rounded is-outlined is-black p-6 is-large is-flex is-flex-direction-column is-align-items-start has-text-left" style="white-space: normal;" href="/documentation.html"> <span class="is-size-4">Documentation</span><span class="is-size-6">strongSwan is extensively documented</span> </a></p> 187<p><a class="button is-rounded is-outlined is-black p-6 is-large is-flex is-flex-direction-column is-align-items-start has-text-left" style="white-space: normal;" href="/support.html"> <span class="is-size-4">Support</span><span class="is-size-6">Free and commecial support is available</span> </a></p> 188</div> 189</section> 190<footer class="footer"> 191 <div class="container"> 192 <div class="columns"> 193 <div class="column"> 194 <strong>strongSwan Project</strong> 195 <ul> 196 <li><a href="/download.html">Downloads</a></li> 197 <li><a href="/license.html">License</a></li> 198 <li><a href="/about.html">About</a></li> 199 <li><a href="/blog/">Blog</a> (<a href="/blog/feed.rss">RSS</a>)</li> 200 </ul> 201 </div> 202 <div class="column"> 203 <strong>Help</strong> 204 <ul> 205 <li><a href="/documentation.html">Documentation</a></li> 206 <li><a href="/support.html">Support</a></li> 207 </ul> 208 </div> 209 <div class="column"> 210 <strong>Social</strong> 211 <ul> 212 <li><a href="https://github.com/strongswan"> 213 <span class="icon-text"> 214 <span class="icon"> 215 <i class="fa-brands fa-github"></i> 216 </span> 217 GitHub 218 </span> 219 </a></li> 220 <li><a href="https://bsky.app/profile/strongswan.org"> 221 <span class="icon-text"> 222 <span class="icon"> 223 <i class="fa-brands fa-bluesky"></i> 224 </span> 225 Bluesky 226 </span> 227 </a></li> 228 <li><a href="https://x.com/strongswan"> 229 <span class="icon-text"> 230 <span class="icon"> 231 <i class="fa-brands fa-x-twitter"></i> 232 </span> 233 X/Twitter 234 </span> 235 </a></li> 236 <li><a href="https://www.facebook.com/pages/strongSwan/222380261260881"> 237 <span class="icon-text"> 238 <span class="icon"> 239 <i class="fa-brands fa-facebook"></i> 240 </span> 241 Facebook 242 </span> 243 </a></li> 244 </ul> 245 </div> 246 <div class="column is-2 is-three-fifths-mobile"> 247 <strong class="block is-block">Main Sponsors</strong> 248 <a class="block is-block" href="https://www.secunet.com/"><img src="/images/secunet_logo_neg.svg" alt="secunet"></a> 249 <a class="block is-block" href="https://www.codelabs.ch/"><img src="/images/codelabs_logo_rgb_neg.png" alt="codelabs"></a> 250 </div> 251 </div> 252 <div class="columns mt-6"> 253 <div class="column"> 254 <p> 255 <strong>© 2026</strong> by The strongSwan Team 256 </p> 257 </div> 258 <div class="column has-text-right-tablet"> 259 <p> 260 <a class="block is-block" href="/imprint.html">Imprint</a> 261 </p> 262 </div> 263 </div> 264 </div> 265 </footer> 266
266<script src="/js/jquery-3.6.1.min.js"></script>
266 267
267<script src="/js/site.js"></script>
267 268 269 </body> 270</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.