strongswan - OpenSource IPsec-based VPN Solution

Property Value
Distribution openSUSE Leap 42.3
Repository openSUSE Oss all
Package name strongswan
Package version 5.2.2
Package release 9.4
Package architecture x86_64
Package type rpm
Installed size 2.29 KB
Download size 64.04 KB
Official Mirror
StrongSwan is an OpenSource IPsec-based VPN Solution for Linux
* runs both on Linux 2.4 (KLIPS IPsec) and Linux 2.6 (NETKEY IPsec) kernels
* implements both the IKEv1 and IKEv2 (RFC 4306) key exchange protocols
* Fully tested support of IPv6 IPsec tunnel and transport connections
* Dynamical IP address and interface update with IKEv2 MOBIKE (RFC 4555)
* Automatic insertion and deletion of IPsec-policy-based firewall rules
* Strong 128/192/256 bit AES or Camellia encryption, 3DES support
* NAT-Traversal via UDP encapsulation and port floating (RFC 3947)
* Dead Peer Detection (DPD, RFC 3706) takes care of dangling tunnels
* Static virtual IPs and IKEv1 ModeConfig pull and push modes
* XAUTH server and client functionality on top of IKEv1 Main Mode authentication
* Virtual IP address pool managed by IKE daemon or SQL database
* Secure IKEv2 EAP user authentication (EAP-SIM, EAP-AKA, EAP-MSCHAPv2, etc.)
* Optional relaying of EAP messages to AAA server via EAP-RADIUS plugin
* Support of IKEv2 Multiple Authentication Exchanges (RFC 4739)
* Authentication based on X.509 certificates or preshared keys
* Generation of a default self-signed certificate during first strongSwan startup
* Retrieval and local caching of Certificate Revocation Lists via HTTP or LDAP
* Full support of the Online Certificate Status Protocol (OCSP, RCF 2560).
* CA management (OCSP and CRL URIs, default LDAP server)
* Powerful IPsec policies based on wildcards or intermediate CAs
* Group policies based on X.509 attribute certificates (RFC 3281)
* Storage of RSA private keys and certificates on a smartcard (PKCS #11 interface)
* Modular plugins for crypto algorithms and relational database interfaces
* Support of elliptic curve DH groups and ECDSA certificates (Suite B, RFC 4869)
* Optional built-in integrity and crypto tests for plugins and libraries
* Smooth Linux desktop integration via the strongSwan NetworkManager applet
This package triggers the installation of both, IKEv1 and IKEv2 daemons.


Package Version Architecture Repository
strongswan - - -


Name Value
rpmlib(CompressedFileNames) <= 3.0.4-1
rpmlib(PayloadFilesHavePrefix) <= 4.0-1
rpmlib(PayloadIsLzma) <= 4.4.6-1
strongswan-ipsec = 5.2.2
systemd -


Name Value
strongswan = 5.2.2-9.4
strongswan(x86-64) = 5.2.2-9.4


Type URL
Binary Package strongswan-5.2.2-9.4.x86_64.rpm
Source Package strongswan-5.2.2-9.4.src.rpm

Install Howto

Install strongswan rpm package:

# zypper install strongswan

See Also

Package Description
strongswan-doc-5.2.2-9.4.noarch.rpm OpenSource IPsec-based VPN Solution
strongswan-hmac-5.2.2-9.4.x86_64.rpm HMAC files for FIPS-140-2 integrity
strongswan-ipsec-5.2.2-9.4.x86_64.rpm OpenSource IPsec-based VPN Solution
strongswan-libs0-5.2.2-9.4.x86_64.rpm OpenSource IPsec-based VPN Solution
strongswan-mysql-5.2.2-9.4.x86_64.rpm OpenSource IPsec-based VPN Solution
strongswan-nm-5.2.2-9.4.x86_64.rpm OpenSource IPsec-based VPN Solution
strongswan-sqlite-5.2.2-9.4.x86_64.rpm OpenSource IPsec-based VPN Solution
stunnel-5.00-4.1.x86_64.rpm Universal SSL Tunnel
su-wrapper-1.2.0-502.1.x86_64.rpm The su-wrapper Runs Programs as Another User and Group
submin- Web Adminstration Interface to Subversion and git
submin-apache- Dependencies when using Submin with Apache httpd
submin-svn- Dependencies when using Submin with Apache Subversion
subversion-1.9.5-6.3.x86_64.rpm Subversion version control system
subversion-bash-completion-1.9.5-6.3.noarch.rpm Bash Completion for subversion
subversion-devel-1.9.5-6.3.x86_64.rpm Development package for Subversion developers