Skip to content

freeswan.ca is independent. Some links earn us a commission; your price stays the same. How we review

freeswan.ca

strongSwan vs Libreswan: two Linux IPsec projects compared

strongSwan and Libreswan are both open source IKE daemons for IPsec VPNs on Linux, both GPLv2, and both descend from the FreeS/WAN project. They differ in configuration style, crypto library, platform reach and who maintains them.

Updated

Server rack in a server room

Short answer

Both are mature, GPLv2-licensed IKE daemons that let a Linux machine run IPsec VPNs, and both can serve as a site-to-site gateway or a remote access server. Libreswan is the natural pick on distributions that ship it, such as Fedora, RHEL (through EPEL) and Arch Linux, and if you prefer the classic /etc/ipsec.conf format. strongSwan suits you if you want its modular plugin design, the swanctl configuration style, or clients beyond Linux, such as its own Android app. For most standard tunnels, either will do the job, and the deciding factor is usually what your distribution packages and what your team already knows.

Side by side

strongSwanLibreswan
Latest release seen6.1.0, published September 7, 2026 (GitHub)5.4.1, published October 6, 2026 (GitHub); 5.3.3 announced alongside it
LicenceGPLv2; separate non-GPL commercial licence from secunetGPLv2
IKE versionsIKEv1 and IKEv2 in one daemon (IKEv1 added with 5.0 in 2012)IKE versions 1 and 2
Daemoncharon, written from scratchpluto (the name of FreeS/WAN's daemon)
Configurationswanctl.conf via the VICI interface; the older stroke interface and ipsec tool are deprecated/etc/ipsec.conf and /etc/ipsec.secrets
CryptoPlugins, with back ends based on OpenSSL, Botan or wolfSSL among othersNSS crypto library
Kernel IPsec on LinuxLinux kernel IPsec (its docs cover the kernel modules needed)The kernel's built-in XFRM stack
Other platforms in its docsAndroid client, Windows, FreeBSD, macOSFreeBSD and Apple OSX listed on the home page
OriginLaunched 2005 as a fork of FreeS/WANFork of Openswan 2.6.38, itself forked from FreeS/WAN 2.04
StewardIntellectual property acquired by secunet Security Networks AG, June 2022The Libreswan Project

Sources: strongswan.org, docs.strongswan.org, libreswan.org and the GitHub release pages of both projects, checked October 6, 2026. Release numbers change often; check each project's site before you install.

What the two have in common

On Linux, both work the same basic way. The kernel's IPsec code encrypts and decrypts ESP packets, and the userspace daemon (charon for strongSwan, pluto for Libreswan) runs IKE to authenticate peers and install the keys. Both implement IKEv2 as defined in RFC 7296, both move traffic to UDP 4500 when a NAT sits in the path, and both handle site-to-site tunnels and remote access users. Both are distributed under GPLv2 and developed in public on GitHub, where each publishes its releases.

The practical differences are in configuration, packaging and the platforms each project documents. That is why the choice is usually made by your distribution and your existing skills more than by any feature gap.

strongSwan in more detail

strongSwan describes itself as "a comprehensive implementation of the Internet Key Exchange (IKE) protocols that allows securing IP traffic in policy- and route-based IPsec scenarios from simple to very complex." Its about page explains that a new IKE daemon was "written from scratch in a modern object-oriented coding style", and that "the current code base does not share code with its ancestor anymore."

That daemon, charon, started out handling only IKEv2, while IKEv1 was handled by an extended version of FreeS/WAN's pluto. With strongSwan 5.0 in 2012, IKEv1 support moved into the new daemon, "which removed pluto and many other legacy components." Features are added through plugins, and its plugin list includes crypto back ends based on the OpenSSL, Botan and wolfSSL libraries.

Configuration today goes through the Versatile IKE Control Interface (VICI) and the swanctl tool. The documentation marks the stroke interface and the ipsec command line tool as deprecated, so older strongSwan tutorials built on the ipsec command describe the legacy method. The documentation also covers an Android VPN client, Windows clients and Apple IKEv2 configuration profiles.

On licensing, strongSwan's licence page states: "strongSwan is an open-source project distributed under the GPLv2 license." secunet, which acquired the project's intellectual property rights in June 2022, also offers a separate commercial licence for those who cannot use GPL code.

Libreswan in more detail

Libreswan calls itself "a free software implementation of the most widely supported and standardized VPN protocol using 'IPsec' and the Internet Key Exchange ('IKE')." Its home page says it supports IKE versions 1 and 2, and that on Linux "it uses the built-in 'XFRM' IPsec stack (linux-ipsec). It uses the NSS crypto library."

Libreswan "ships as part of many Linux distributions, including Fedora, RHEL/EPEL and Arch Linux", so on those systems you install it with the normal package manager. Configuration lives in /etc/ipsec.conf, with secrets in /etc/ipsec.secrets. Readers who learned IPsec on FreeS/WAN or Openswan will recognize the format.

On October 6, 2026, the Libreswan home page announced releases 5.3.3 and 5.4.1, which address four CVEs. If you run Libreswan, that announcement is worth reading before anything else on this page.

How to choose

  • Use what your distribution ships and supports. Security updates arrive through the normal package channel, which matters more than any feature difference.
  • Need Android or Windows clients from the same project? strongSwan documents both.
  • Working on Fedora, RHEL with EPEL, or Arch Linux? Libreswan is packaged there.
  • Prefer a structured config with a control socket? strongSwan's swanctl and VICI.
  • Prefer the classic conn sections of ipsec.conf? Libreswan.
  • Connecting to a third-party gateway? Either. Both implement IKEv2 as specified in RFC 7296, and the Canadian Centre for Cyber Security notes that IPsec "is an open standard, meaning that anyone can build a client or server which will work with other IPsec implementations."

If you are still deciding whether IPsec is the right protocol at all, read IPsec vs WireGuard and, for company remote access, IPsec vs SSL VPN. The basics of ESP, IKE and tunnel mode are in What is an IPsec VPN?

Where Linux IPsec came from: FreeS/WAN and its forks

Both projects trace their roots to FreeS/WAN, an earlier free IPsec implementation for Linux. According to Libreswan's site, "The FreeS/WAN Project founded in 1997 by John Gilmore and Hugh Daniel." In an essay from 1999 on the project's site, John Gilmore explained the name: the project was called S/WAN, for Secure Wide Area Network, and "since it's free software, we call it FreeS/WAN to distinguish it from various commercial implementations." The same essay set out his aim of securing 5% of internet traffic against passive wiretapping.

The project's archived home page records its end. A notice dated March 1, 2004 says "FreeS/WAN is no longer in active development", adding that its major goal, "ubiquitous Opportunistic Encryption, is unlikely to be reached." Version 2.06, released April 22, 2004, was announced as "the project's final release." The same page pointed users to "both forks of the FreeS/WAN codebase: Openswan and Strongswan."

The family tree, as the projects themselves describe it:

  • Openswan was forked from FreeS/WAN 2.04.
  • strongSwan "was launched in 2005 as a fork of the discontinued FreeS/WAN open source project", integrating an X.509 certificate patch its developers had contributed to FreeS/WAN since 2000. Its current code no longer shares code with FreeS/WAN.
  • Libreswan "was forked from Openswan 2.6.38, which was forked from FreeS/WAN 2.04."

Libreswan's home page sums up the lineage by saying it "has been under active development for over 20 years, going back to The FreeS/WAN Project." strongSwan, by contrast, kept the history but rewrote the code.

This website, freeswan.ca, is an independent publication. It is not connected with the former FreeS/WAN project, its developers, or the strongSwan, Openswan or Libreswan projects.

Before you deploy either

  • Open UDP 500 and 4500 on the gateway, and allow ESP if no NAT is involved.
  • Prefer certificates to a single shared secret for remote users.
  • Disable legacy algorithms you do not need, and keep the package updated.
  • Test with the client platforms your users actually have, especially phones.

Our VPN router guide covers the case where the IPsec gateway is a router rather than a Linux server.

Common questions

Do strongSwan and Libreswan both support IKEv1 and IKEv2?

Yes. Libreswan's home page says it supports IKE versions 1 and 2. strongSwan's new daemon started with IKEv2 only, and IKEv1 support was added to it with strongSwan 5.0 in 2012.

Can a strongSwan server talk to a Libreswan client?

In principle, yes. Both implement the IETF IPsec and IKE standards, and the Canadian Centre for Cyber Security describes IPsec as an open standard that lets any client or server work with other IPsec implementations. You still need matching settings for authentication, identities and algorithms on both sides.

Is strongSwan still open source after secunet acquired it?

Yes. strongSwan's licence page says the project is distributed under the GPLv2 licence. secunet, which acquired the project's intellectual property rights in June 2022, also offers a separate non-GPL commercial licence.

Is this website related to FreeS/WAN?

No. freeswan.ca is an independent guide and has no connection with the former FreeS/WAN project or any of its developers. We describe the project's history only from its archived pages and the pages of its successor projects.

Sources