Use APKPure App
Get strongSwan VPN Client old version APK for Android
An easy to use IKEv2/IPsec-based VPN client.
Official Android port of the popular strongSwan VPN solution.
# FEATURES AND LIMITATIONS #
* Uses the VpnService API featured by Android 4+. Devices by some manufacturers seem to lack for this - strongSwan VPN Client won't work on these devices!
* Uses the IKEv2 key exchange protocol
* Uses IPsec for data traffic
* Full for changed connectivity and mobility through MOBIKE (or reauthentication)
* s name/ EAP authentication (namely EAP-MSCHAPv2, EAP-MD5 and EAP-GTC) as well as RSA/ECDSA private key/certificate authentication to authenticate s, EAP-TLS with client certificates is also ed
* Combined RSA/ECDSA and EAP authentication is ed by using two authentication rounds as defined in RFC 4739
* VPN server certificates are verified against the CA certificates pre-installed or installed by the on the system. The CA or server certificates used to authenticate the server can also be imported directly into the app.
* IKEv2 fragmentation is ed if the VPN server s it (strongSwan does so since 5.2.1)
* Split-tunneling allows sending only certain traffic through the VPN and/or excluding specific traffic from it
* Per-app VPN allows limiting the VPN connection to specific apps, or exclude them from using it
* The IPsec implementation currently s the AES-CBC, AES-GCM, ChaCha20/Poly1305 and SHA1/SHA2 algorithms
* s are currently stored as cleartext in the database (only if stored with a profile)
* VPN profiles may be imported from files
* s managed configurations via enterprise mobility management (EMM)
Details and a changelog can be found on our docs: https://docs.strongswan.org/docs/latest/os/androidVpnClient.html
# PERMISSIONS #
* READ_EXTERNAL_STORAGE: Allows importing VPN profiles and CA certificates from external storage on some Android versions
* QUERY_ALL_PACKAGES: Required on Android 11+ to select apps to ex-/include in VPN profiles and the optional EAP-TNC use case
# EXAMPLE SERVER CONFIGURATION #
Example server configurations may be found in our docs: https://docs.strongswan.org/docs/latest/os/androidVpnClient.html#_server_configuration
Please note that the host name (or IP address) configured with a VPN profile in the app *must be* contained in the server certificate as subjectAltName extension.
# #
Please post bug reports and feature requests via GitHub: https://github.com/strongswan/strongswan/issues/new/choose
If you do so, please include information about your device (manufacturer, model, OS version etc.).
The log file written by the key exchange service can be sent directly from within the application.
ed by
Darren Boykin
Requires Android
Android 5.0+
Category
Report
Last updated on Apr 4, 2025
# 2.5.5 #
- Fix initiating managed profiles as Always-on VPN
# 2.5.4 #
- Fix issues when reestablishing the connection
# 2.5.3 #
- Add for distributing s in managed profiles
- Add for importing profile files with s
- Fix crash when editing of managed profiles
- Fix crash when re-importing an already existing profile
strongSwan VPN Client
strongSwan Project
2.5.5
Trusted App