notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC
Ukraine
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
After the ports freeze to fix some stuff, the freeze is over. I have some work to do before FreshPorts can start processing commits again before it can start processing again. I've created an issue for that.
Port details on branch 2026Q2
strongswan Open Source IKEv2 IPsec-based VPN solution
6.0.7 security on this many watch lists=0 search for ports that depend on this port An older version of this port was marked as vulnerable. Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 6.0.7Version of this port present on the latest quarterly branch.
Maintainer: strongswan@nanoteq.com search for ports maintained by this maintainer
Port Added: 2026-04-06 22:48:09
Last Update: 2026-06-08 15:23:45
Commit Hash: 5a5c707
Also Listed In: net-vpn
License: GPLv2
WWW:
https://www.strongswan.org
Description:
Strongswan is an open source IPsec-based VPN solution. Strongswan for FreeBSD implements both the IKEv1 and IKEv2 (RFC 5996) key exchange protocols.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
pkg-plist: as obtained via: make generate-plist
Expand this list (441 items)
Collapse this list.
  1. @ldconfig
  2. /usr/local/share/licenses/strongswan-6.0.7/catalog.mk
  3. /usr/local/share/licenses/strongswan-6.0.7/LICENSE
  4. /usr/local/share/licenses/strongswan-6.0.7/GPLv2
  5. bin/pki
  6. @comment bin/tpm_extendpcr
  7. @sample etc/strongswan.conf.sample
  8. @sample etc/strongswan.d/charon-cmd.conf.sample
  9. @sample etc/strongswan.d/charon-cmd/blowfish.conf.sample
  10. @sample etc/strongswan.d/charon-cmd/cmac.conf.sample
  11. @sample etc/strongswan.d/charon-cmd/constraints.conf.sample
  12. @comment @sample etc/strongswan.d/charon-cmd/ctr.conf.sample
  13. @sample etc/strongswan.d/charon-cmd/curl.conf.sample
  14. @sample etc/strongswan.d/charon-cmd/drbg.conf.sample
  15. @sample etc/strongswan.d/charon-cmd/eap-identity.conf.sample
  16. @sample etc/strongswan.d/charon-cmd/eap-md5.conf.sample
  17. @sample etc/strongswan.d/charon-cmd/eap-mschapv2.conf.sample
  18. @sample etc/strongswan.d/charon-cmd/eap-peap.conf.sample
  19. @sample etc/strongswan.d/charon-cmd/eap-tls.conf.sample
  20. @sample etc/strongswan.d/charon-cmd/eap-ttls.conf.sample
  21. @comment @sample etc/strongswan.d/charon-cmd/fips-prf.conf.sample
  22. @sample etc/strongswan.d/charon-cmd/gcm.conf.sample
  23. @comment @sample etc/strongswan.d/charon-cmd/gmp.conf.sample
  24. @sample etc/strongswan.d/charon-cmd/kdf.conf.sample
  25. @comment @sample etc/strongswan.d/charon-cmd/kernel-libipsec.conf.sample
  26. @sample etc/strongswan.d/charon-cmd/kernel-pfkey.conf.sample
  27. @sample etc/strongswan.d/charon-cmd/kernel-pfroute.conf.sample
  28. @comment @sample etc/strongswan.d/charon-cmd/ldap.conf.sample
  29. @sample etc/strongswan.d/charon-cmd/md4.conf.sample
  30. @comment @sample etc/strongswan.d/charon-cmd/mgf1.conf.sample
  31. @sample etc/strongswan.d/charon-cmd/ml.conf.sample
  32. @sample etc/strongswan.d/charon-cmd/nonce.conf.sample
  33. @sample etc/strongswan.d/charon-cmd/openssl.conf.sample
  34. @sample etc/strongswan.d/charon-cmd/pem.conf.sample
  35. @sample etc/strongswan.d/charon-cmd/pkcs1.conf.sample
  36. @comment @sample etc/strongswan.d/charon-cmd/pkcs11.conf.sample
  37. @sample etc/strongswan.d/charon-cmd/pkcs7.conf.sample
  38. @sample etc/strongswan.d/charon-cmd/pkcs8.conf.sample
  39. @sample etc/strongswan.d/charon-cmd/pubkey.conf.sample
  40. @sample etc/strongswan.d/charon-cmd/random.conf.sample
  41. @sample etc/strongswan.d/charon-cmd/resolve.conf.sample
  42. @sample etc/strongswan.d/charon-cmd/revocation.conf.sample
  43. @sample etc/strongswan.d/charon-cmd/socket-default.conf.sample
  44. @sample etc/strongswan.d/charon-cmd/sshkey.conf.sample
  45. @comment @sample etc/strongswan.d/charon-cmd/tpm.conf.sample
  46. @sample etc/strongswan.d/charon-cmd/x509.conf.sample
  47. @comment @sample etc/strongswan.d/charon-cmd/xauth-generic.conf.sample
  48. @sample etc/strongswan.d/charon-cmd/xcbc.conf.sample
  49. @sample etc/strongswan.d/charon-logging.conf.sample
  50. @sample etc/strongswan.d/charon.conf.sample
  51. @sample etc/strongswan.d/charon/addrblock.conf.sample
  52. @comment @sample etc/strongswan.d/charon/attr-sql.conf.sample
  53. @sample etc/strongswan.d/charon/attr.conf.sample
  54. @sample etc/strongswan.d/charon/blowfish.conf.sample
  55. @sample etc/strongswan.d/charon/cmac.conf.sample
  56. @sample etc/strongswan.d/charon/constraints.conf.sample
  57. @sample etc/strongswan.d/charon/counters.conf.sample
  58. @comment @sample etc/strongswan.d/charon/ctr.conf.sample
  59. @sample etc/strongswan.d/charon/curl.conf.sample
  60. @comment etc/strongswan.d/charon/dhcp.conf.sample
  61. @sample etc/strongswan.d/charon/dnskey.conf.sample
  62. @sample etc/strongswan.d/charon/drbg.conf.sample
  63. @comment @sample etc/strongswan.d/starter.conf.sample
  64. @comment @sample etc/strongswan.d/charon/eap-aka-3gpp2.conf.sample
  65. @comment @sample etc/strongswan.d/charon/eap-aka.conf.sample
  66. @comment @sample etc/strongswan.d/charon/eap-dynamic.conf.sample
  67. @sample etc/strongswan.d/charon/eap-identity.conf.sample
  68. @sample etc/strongswan.d/charon/eap-md5.conf.sample
  69. @sample etc/strongswan.d/charon/eap-mschapv2.conf.sample
  70. @sample etc/strongswan.d/charon/eap-peap.conf.sample
  71. @comment @sample etc/strongswan.d/charon/eap-radius.conf.sample
  72. @comment @sample etc/strongswan.d/charon/eap-sim-file.conf.sample
  73. @comment @sample etc/strongswan.d/charon/eap-sim.conf.sample
  74. @sample etc/strongswan.d/charon/eap-tls.conf.sample
  75. @sample etc/strongswan.d/charon/eap-ttls.conf.sample
  76. @comment @sample etc/strongswan.d/charon/farp.conf.sample
  77. @comment @sample etc/strongswan.d/charon/fips-prf.conf.sample
  78. @sample etc/strongswan.d/charon/gcm.conf.sample
  79. @comment @sample etc/strongswan.d/charon/gmp.conf.sample
  80. @comment @sample etc/strongswan.d/charon/ipseckey.conf.sample
  81. @sample etc/strongswan.d/charon/kdf.conf.sample
  82. @comment @sample etc/strongswan.d/charon/kernel-libipsec.conf.sample
  83. @sample etc/strongswan.d/charon/kernel-pfkey.conf.sample
  84. @sample etc/strongswan.d/charon/kernel-pfroute.conf.sample
  85. @comment @sample etc/strongswan.d/charon/ldap.conf.sample
  86. @comment @sample etc/strongswan.d/charon/load-tester.conf.sample
  87. @sample etc/strongswan.d/charon/md4.conf.sample
  88. @comment @sample etc/strongswan.d/charon/mgf1.conf.sample
  89. @sample etc/strongswan.d/charon/ml.conf.sample
  90. @comment @sample etc/strongswan.d/charon/mysql.conf.sample
  91. @sample etc/strongswan.d/charon/nonce.conf.sample
  92. @sample etc/strongswan.d/charon/openssl.conf.sample
  93. @comment @sample etc/strongswan.d/charon/padlock.conf.sample
  94. @sample etc/strongswan.d/charon/pem.conf.sample
  95. @sample etc/strongswan.d/charon/pgp.conf.sample
  96. @sample etc/strongswan.d/charon/pkcs1.conf.sample
  97. @comment @sample etc/strongswan.d/charon/pkcs11.conf.sample
  98. @sample etc/strongswan.d/charon/pkcs7.conf.sample
  99. @sample etc/strongswan.d/charon/pkcs8.conf.sample
  100. @sample etc/strongswan.d/charon/pubkey.conf.sample
  101. @sample etc/strongswan.d/charon/random.conf.sample
  102. @sample etc/strongswan.d/charon/resolve.conf.sample
  103. @sample etc/strongswan.d/charon/revocation.conf.sample
  104. @comment @sample etc/strongswan.d/charon/smp.conf.sample
  105. @sample etc/strongswan.d/charon/socket-default.conf.sample
  106. @comment @sample etc/strongswan.d/charon/sql.conf.sample
  107. @comment @sample etc/strongswan.d/charon/stroke.conf.sample
  108. @comment @sample etc/strongswan.d/charon/sqlite.conf.sample
  109. @sample etc/strongswan.d/charon/sshkey.conf.sample
  110. @comment @sample etc/strongswan.d/charon/test-vectors.conf.sample
  111. @comment @sample etc/strongswan.d/charon/tpm.conf.sample
  112. @comment @sample etc/strongswan.d/charon/unbound.conf.sample
  113. @comment @sample etc/strongswan.d/charon/unity.conf.sample
  114. @sample etc/strongswan.d/charon/updown.conf.sample
  115. @sample etc/strongswan.d/charon/vici.conf.sample
  116. @sample etc/strongswan.d/charon/whitelist.conf.sample
  117. @sample etc/strongswan.d/charon/x509.conf.sample
  118. @comment @sample etc/strongswan.d/charon/xauth-eap.conf.sample
  119. @sample etc/strongswan.d/charon/xauth-generic.conf.sample
  120. @comment @sample etc/strongswan.d/charon/xauth-pam.conf.sample
  121. @sample etc/strongswan.d/charon/xcbc.conf.sample
  122. @sample etc/strongswan.d/iptfs.conf.sample
  123. @sample etc/strongswan.d/pki.conf.sample
  124. @comment @sample etc/strongswan.d/pool.conf.sample
  125. @sample etc/strongswan.d/swanctl.conf.sample
  126. @comment @sample etc/ipsec.conf.sample
  127. @comment @sample etc/ipsec.secrets.sample
  128. @sample etc/swanctl/swanctl.conf.sample
  129. include/libvici.h
  130. lib/ipsec/libcharon.la
  131. lib/ipsec/libcharon.so
  132. lib/ipsec/libcharon.so.0
  133. lib/ipsec/libcharon.so.0.0.0
  134. @comment lib/ipsec/libipsec.la
  135. @comment lib/ipsec/libipsec.so
  136. @comment lib/ipsec/libipsec.so.0
  137. @comment lib/ipsec/libipsec.so.0.0.0
  138. @comment lib/ipsec/libradius.la
  139. @comment lib/ipsec/libradius.so
  140. @comment lib/ipsec/libradius.so.0
  141. @comment lib/ipsec/libradius.so.0.0.0
  142. @comment lib/ipsec/libsimaka.la
  143. @comment lib/ipsec/libsimaka.so
  144. @comment lib/ipsec/libsimaka.so.0
  145. @comment lib/ipsec/libsimaka.so.0.0.0
  146. lib/ipsec/libstrongswan.la
  147. lib/ipsec/libstrongswan.so
  148. lib/ipsec/libstrongswan.so.0
  149. lib/ipsec/libstrongswan.so.0.0.0
  150. lib/ipsec/libtls.la
  151. lib/ipsec/libtls.so
  152. lib/ipsec/libtls.so.0
  153. lib/ipsec/libtls.so.0.0.0
  154. @comment lib/ipsec/libtpmtss.la
  155. @comment lib/ipsec/libtpmtss.so
  156. @comment lib/ipsec/libtpmtss.so.0
  157. @comment lib/ipsec/libtpmtss.so.0.0.0
  158. lib/ipsec/libvici.la
  159. lib/ipsec/libvici.so
  160. lib/ipsec/libvici.so.0
  161. lib/ipsec/libvici.so.0.0.0
  162. lib/ipsec/plugins/libstrongswan-addrblock.la
  163. lib/ipsec/plugins/libstrongswan-addrblock.so
  164. @comment lib/ipsec/plugins/libstrongswan-attr-sql.la
  165. @comment lib/ipsec/plugins/libstrongswan-attr-sql.so
  166. lib/ipsec/plugins/libstrongswan-attr.la
  167. lib/ipsec/plugins/libstrongswan-attr.so
  168. lib/ipsec/plugins/libstrongswan-blowfish.la
  169. lib/ipsec/plugins/libstrongswan-blowfish.so
  170. lib/ipsec/plugins/libstrongswan-cmac.la
  171. lib/ipsec/plugins/libstrongswan-cmac.so
  172. lib/ipsec/plugins/libstrongswan-constraints.la
  173. lib/ipsec/plugins/libstrongswan-constraints.so
  174. lib/ipsec/plugins/libstrongswan-counters.la
  175. lib/ipsec/plugins/libstrongswan-counters.so
  176. @comment lib/ipsec/plugins/libstrongswan-ctr.la
  177. @comment lib/ipsec/plugins/libstrongswan-ctr.so
  178. lib/ipsec/plugins/libstrongswan-curl.la
  179. lib/ipsec/plugins/libstrongswan-curl.so
  180. @comment lib/ipsec/plugins/libstrongswan-dhcp.la
  181. @comment lib/ipsec/plugins/libstrongswan-dhcp.so
  182. lib/ipsec/plugins/libstrongswan-dnskey.la
  183. lib/ipsec/plugins/libstrongswan-dnskey.so
  184. lib/ipsec/plugins/libstrongswan-drbg.la
  185. lib/ipsec/plugins/libstrongswan-drbg.so
  186. @comment lib/ipsec/plugins/libstrongswan-eap-aka-3gpp2.la
  187. @comment lib/ipsec/plugins/libstrongswan-eap-aka-3gpp2.so
  188. @comment lib/ipsec/plugins/libstrongswan-eap-aka.la
  189. @comment lib/ipsec/plugins/libstrongswan-eap-aka.so
  190. @comment lib/ipsec/plugins/libstrongswan-eap-dynamic.la
  191. @comment lib/ipsec/plugins/libstrongswan-eap-dynamic.so
  192. lib/ipsec/plugins/libstrongswan-eap-identity.la
  193. lib/ipsec/plugins/libstrongswan-eap-identity.so
  194. lib/ipsec/plugins/libstrongswan-eap-md5.la
  195. lib/ipsec/plugins/libstrongswan-eap-md5.so
  196. @comment lib/ipsec/plugins/libstrongswan-fips-prf.la
  197. @comment lib/ipsec/plugins/libstrongswan-fips-prf.so
  198. lib/ipsec/plugins/libstrongswan-eap-mschapv2.la
  199. lib/ipsec/plugins/libstrongswan-eap-mschapv2.so
  200. lib/ipsec/plugins/libstrongswan-eap-peap.la
  201. lib/ipsec/plugins/libstrongswan-eap-peap.so
  202. @comment lib/ipsec/plugins/libstrongswan-eap-radius.la
  203. @comment lib/ipsec/plugins/libstrongswan-eap-radius.so
  204. @comment lib/ipsec/plugins/libstrongswan-eap-sim-file.la
  205. @comment lib/ipsec/plugins/libstrongswan-eap-sim-file.so
  206. @comment lib/ipsec/plugins/libstrongswan-eap-sim.la
  207. @comment lib/ipsec/plugins/libstrongswan-eap-sim.so
  208. lib/ipsec/plugins/libstrongswan-eap-tls.la
  209. lib/ipsec/plugins/libstrongswan-eap-tls.so
  210. lib/ipsec/plugins/libstrongswan-eap-ttls.la
  211. lib/ipsec/plugins/libstrongswan-eap-ttls.so
  212. @comment lib/ipsec/plugins/libstrongswan-farp.la
  213. @comment lib/ipsec/plugins/libstrongswan-farp.so
  214. lib/ipsec/plugins/libstrongswan-gcm.la
  215. lib/ipsec/plugins/libstrongswan-gcm.so
  216. @comment lib/ipsec/plugins/libstrongswan-gmp.la
  217. @comment lib/ipsec/plugins/libstrongswan-gmp.so
  218. @comment lib/ipsec/plugins/libstrongswan-ipseckey.la
  219. @comment lib/ipsec/plugins/libstrongswan-ipseckey.so
  220. lib/ipsec/plugins/libstrongswan-kdf.la
  221. lib/ipsec/plugins/libstrongswan-kdf.so
  222. @comment lib/ipsec/plugins/libstrongswan-kernel-libipsec.la
  223. @comment lib/ipsec/plugins/libstrongswan-kernel-libipsec.so
  224. lib/ipsec/plugins/libstrongswan-kernel-pfkey.la
  225. lib/ipsec/plugins/libstrongswan-kernel-pfkey.so
  226. lib/ipsec/plugins/libstrongswan-kernel-pfroute.la
  227. lib/ipsec/plugins/libstrongswan-kernel-pfroute.so
  228. @comment lib/ipsec/plugins/libstrongswan-ldap.la
  229. @comment lib/ipsec/plugins/libstrongswan-ldap.so
  230. @comment lib/ipsec/plugins/libstrongswan-load-tester.la
  231. @comment lib/ipsec/plugins/libstrongswan-load-tester.so
  232. lib/ipsec/plugins/libstrongswan-md4.la
  233. lib/ipsec/plugins/libstrongswan-md4.so
  234. @comment lib/ipsec/plugins/libstrongswan-mgf1.la
  235. @comment lib/ipsec/plugins/libstrongswan-mgf1.so
  236. lib/ipsec/plugins/libstrongswan-ml.la
  237. lib/ipsec/plugins/libstrongswan-ml.so
  238. @comment lib/ipsec/plugins/libstrongswan-mysql.la
  239. @comment lib/ipsec/plugins/libstrongswan-mysql.so
  240. lib/ipsec/plugins/libstrongswan-nonce.la
  241. lib/ipsec/plugins/libstrongswan-nonce.so
  242. lib/ipsec/plugins/libstrongswan-openssl.la
  243. lib/ipsec/plugins/libstrongswan-openssl.so
  244. @comment lib/ipsec/plugins/libstrongswan-padlock.la
  245. @comment lib/ipsec/plugins/libstrongswan-padlock.so
  246. lib/ipsec/plugins/libstrongswan-pem.la
  247. lib/ipsec/plugins/libstrongswan-pem.so
  248. lib/ipsec/plugins/libstrongswan-pgp.la
  249. lib/ipsec/plugins/libstrongswan-pgp.so
  250. lib/ipsec/plugins/libstrongswan-pkcs1.la
  251. lib/ipsec/plugins/libstrongswan-pkcs1.so
  252. @comment lib/ipsec/plugins/libstrongswan-pkcs11.la
  253. @comment lib/ipsec/plugins/libstrongswan-pkcs11.so
  254. lib/ipsec/plugins/libstrongswan-pkcs7.la
  255. lib/ipsec/plugins/libstrongswan-pkcs7.so
  256. lib/ipsec/plugins/libstrongswan-pkcs8.la
  257. lib/ipsec/plugins/libstrongswan-pkcs8.so
  258. lib/ipsec/plugins/libstrongswan-pubkey.la
  259. lib/ipsec/plugins/libstrongswan-pubkey.so
  260. lib/ipsec/plugins/libstrongswan-random.la
  261. lib/ipsec/plugins/libstrongswan-random.so
  262. lib/ipsec/plugins/libstrongswan-resolve.la
  263. lib/ipsec/plugins/libstrongswan-resolve.so
  264. lib/ipsec/plugins/libstrongswan-revocation.la
  265. lib/ipsec/plugins/libstrongswan-revocation.so
  266. @comment lib/ipsec/plugins/libstrongswan-smp.la
  267. @comment lib/ipsec/plugins/libstrongswan-smp.so
  268. lib/ipsec/plugins/libstrongswan-socket-default.la
  269. lib/ipsec/plugins/libstrongswan-socket-default.so
  270. @comment lib/ipsec/plugins/libstrongswan-sql.la
  271. @comment lib/ipsec/plugins/libstrongswan-sql.so
  272. @comment lib/ipsec/plugins/libstrongswan-sqlite.la
  273. @comment lib/ipsec/plugins/libstrongswan-sqlite.so
  274. lib/ipsec/plugins/libstrongswan-sshkey.la
  275. lib/ipsec/plugins/libstrongswan-sshkey.so
  276. @comment lib/ipsec/plugins/libstrongswan-stroke.la
  277. @comment lib/ipsec/plugins/libstrongswan-stroke.so
  278. @comment lib/ipsec/plugins/libstrongswan-test-vectors.la
  279. @comment lib/ipsec/plugins/libstrongswan-test-vectors.so
  280. @comment lib/ipsec/plugins/libstrongswan-tpm.la
  281. @comment lib/ipsec/plugins/libstrongswan-tpm.so
  282. @comment lib/ipsec/plugins/libstrongswan-unbound.la
  283. @comment lib/ipsec/plugins/libstrongswan-unbound.so
  284. @comment lib/ipsec/plugins/libstrongswan-unity.la
  285. @comment lib/ipsec/plugins/libstrongswan-unity.so
  286. lib/ipsec/plugins/libstrongswan-updown.la
  287. lib/ipsec/plugins/libstrongswan-updown.so
  288. lib/ipsec/plugins/libstrongswan-vici.la
  289. lib/ipsec/plugins/libstrongswan-vici.so
  290. lib/ipsec/plugins/libstrongswan-whitelist.la
  291. lib/ipsec/plugins/libstrongswan-whitelist.so
  292. lib/ipsec/plugins/libstrongswan-x509.la
  293. lib/ipsec/plugins/libstrongswan-x509.so
  294. @comment lib/ipsec/plugins/libstrongswan-xauth-eap.la
  295. @comment lib/ipsec/plugins/libstrongswan-xauth-eap.so
  296. lib/ipsec/plugins/libstrongswan-xauth-generic.la
  297. lib/ipsec/plugins/libstrongswan-xauth-generic.so
  298. @comment lib/ipsec/plugins/libstrongswan-xauth-pam.la
  299. @comment lib/ipsec/plugins/libstrongswan-xauth-pam.so
  300. lib/ipsec/plugins/libstrongswan-xcbc.la
  301. lib/ipsec/plugins/libstrongswan-xcbc.so
  302. libexec/ipsec/_updown
  303. libexec/ipsec/charon
  304. @comment libexec/ipsec/starter
  305. @comment libexec/ipsec/stroke
  306. @comment libexec/ipsec/load-tester
  307. @comment libexec/ipsec/pool
  308. libexec/ipsec/whitelist
  309. share/man/man1/pki---acert.1.gz
  310. share/man/man1/pki---dn.1.gz
  311. share/man/man1/pki---est.1.gz
  312. share/man/man1/pki---estca.1.gz
  313. share/man/man1/pki---gen.1.gz
  314. share/man/man1/pki---issue.1.gz
  315. share/man/man1/pki---keyid.1.gz
  316. share/man/man1/pki---ocsp.1.gz
  317. share/man/man1/pki---pkcs7.1.gz
  318. share/man/man1/pki---print.1.gz
  319. share/man/man1/pki---pub.1.gz
  320. share/man/man1/pki---req.1.gz
  321. share/man/man1/pki---scep.1.gz
  322. share/man/man1/pki---scepca.1.gz
  323. share/man/man1/pki---self.1.gz
  324. share/man/man1/pki---signcrl.1.gz
  325. share/man/man1/pki---verify.1.gz
  326. share/man/man1/pki.1.gz
  327. @comment share/man/man5/ipsec.conf.5.gz
  328. @comment share/man/man5/ipsec.secrets.5.gz
  329. @comment share/man/man8/ipsec.8.gz
  330. share/man/man5/strongswan.conf.5.gz
  331. share/man/man5/swanctl.conf.5.gz
  332. share/man/man8/charon-cmd.8.gz
  333. share/man/man8/swanctl.8.gz
  334. sbin/charon-cmd
  335. @comment sbin/ipsec
  336. sbin/swanctl
  337. share/strongswan/templates/config/plugins/addrblock.conf
  338. @comment share/strongswan/templates/config/plugins/attr-sql.conf
  339. share/strongswan/templates/config/plugins/attr.conf
  340. share/strongswan/templates/config/plugins/blowfish.conf
  341. share/strongswan/templates/config/plugins/cmac.conf
  342. share/strongswan/templates/config/plugins/constraints.conf
  343. share/strongswan/templates/config/plugins/counters.conf
  344. @comment share/strongswan/templates/config/plugins/ctr.conf
  345. share/strongswan/templates/config/plugins/curl.conf
  346. @comment share/strongswan/templates/config/plugins/dhcp.conf
  347. share/strongswan/templates/config/plugins/dnskey.conf
  348. share/strongswan/templates/config/plugins/drbg.conf
  349. @comment share/strongswan/templates/config/plugins/eap-aka-3gpp2.conf
  350. @comment share/strongswan/templates/config/plugins/eap-aka.conf
  351. @comment share/strongswan/templates/config/plugins/eap-dynamic.conf
  352. share/strongswan/templates/config/plugins/eap-identity.conf
  353. share/strongswan/templates/config/plugins/eap-md5.conf
  354. share/strongswan/templates/config/plugins/eap-mschapv2.conf
  355. share/strongswan/templates/config/plugins/eap-peap.conf
  356. @comment share/strongswan/templates/config/plugins/eap-radius.conf
  357. @comment share/strongswan/templates/config/plugins/eap-sim-file.conf
  358. @comment share/strongswan/templates/config/plugins/eap-sim.conf
  359. share/strongswan/templates/config/plugins/eap-tls.conf
  360. share/strongswan/templates/config/plugins/eap-ttls.conf
  361. @comment share/strongswan/templates/config/plugins/farp.conf
  362. @comment share/strongswan/templates/config/plugins/fips-prf.conf
  363. share/strongswan/templates/config/plugins/gcm.conf
  364. @comment share/strongswan/templates/config/plugins/gmp.conf
  365. @comment share/strongswan/templates/config/plugins/ipseckey.conf
  366. share/strongswan/templates/config/plugins/kdf.conf
  367. @comment share/strongswan/templates/config/plugins/kernel-libipsec.conf
  368. share/strongswan/templates/config/plugins/kernel-pfkey.conf
  369. share/strongswan/templates/config/plugins/kernel-pfroute.conf
  370. @comment share/strongswan/templates/config/plugins/ldap.conf
  371. @comment share/strongswan/templates/config/plugins/load-tester.conf
  372. share/strongswan/templates/config/plugins/md4.conf
  373. @comment share/strongswan/templates/config/plugins/mgf1.conf
  374. share/strongswan/templates/config/plugins/ml.conf
  375. @comment share/strongswan/templates/config/plugins/mysql.conf
  376. share/strongswan/templates/config/plugins/nonce.conf
  377. share/strongswan/templates/config/plugins/openssl.conf
  378. @comment share/strongswan/templates/config/plugins/padlock.conf
  379. share/strongswan/templates/config/plugins/pem.conf
  380. share/strongswan/templates/config/plugins/pgp.conf
  381. share/strongswan/templates/config/plugins/pkcs1.conf
  382. @comment share/strongswan/templates/config/plugins/pkcs11.conf
  383. share/strongswan/templates/config/plugins/pkcs7.conf
  384. share/strongswan/templates/config/plugins/pkcs8.conf
  385. share/strongswan/templates/config/plugins/pubkey.conf
  386. share/strongswan/templates/config/plugins/random.conf
  387. share/strongswan/templates/config/plugins/resolve.conf
  388. share/strongswan/templates/config/plugins/revocation.conf
  389. @comment share/strongswan/templates/config/plugins/smp.conf
  390. share/strongswan/templates/config/plugins/socket-default.conf
  391. @comment share/strongswan/templates/config/plugins/sql.conf
  392. @comment share/strongswan/templates/config/plugins/sqlite.conf
  393. share/strongswan/templates/config/plugins/sshkey.conf
  394. @comment share/strongswan/templates/config/plugins/stroke.conf
  395. @comment share/strongswan/templates/config/strongswan.d/starter.conf
  396. @comment share/strongswan/templates/config/plugins/test-vectors.conf
  397. @comment share/strongswan/templates/config/plugins/tpm.conf
  398. @comment share/strongswan/templates/config/plugins/unbound.conf
  399. @comment share/strongswan/templates/config/plugins/unity.conf
  400. share/strongswan/templates/config/plugins/updown.conf
  401. share/strongswan/templates/config/plugins/vici.conf
  402. share/strongswan/templates/config/plugins/whitelist.conf
  403. share/strongswan/templates/config/plugins/x509.conf
  404. @comment share/strongswan/templates/config/plugins/xauth-eap.conf
  405. share/strongswan/templates/config/plugins/xauth-generic.conf
  406. @comment share/strongswan/templates/config/plugins/xauth-pam.conf
  407. share/strongswan/templates/config/plugins/xcbc.conf
  408. share/strongswan/templates/config/strongswan.conf
  409. share/strongswan/templates/config/strongswan.d/charon-cmd.conf
  410. share/strongswan/templates/config/strongswan.d/charon-logging.conf
  411. share/strongswan/templates/config/strongswan.d/charon.conf
  412. share/strongswan/templates/config/strongswan.d/iptfs.conf
  413. share/strongswan/templates/config/strongswan.d/pki.conf
  414. @comment share/strongswan/templates/config/strongswan.d/pool.conf
  415. share/strongswan/templates/config/strongswan.d/swanctl.conf
  416. @comment share/strongswan/templates/database/sql/mysql.sql
  417. @comment share/strongswan/templates/database/sql/sqlite.sql
  418. @dir etc/swanctl/conf.d
  419. @dir etc/swanctl/ecdsa
  420. @dir etc/swanctl/pkcs12
  421. @dir etc/swanctl/pkcs8
  422. @dir etc/swanctl/private
  423. @dir etc/swanctl/pubkey
  424. @dir etc/swanctl/rsa
  425. @dir etc/swanctl/x509
  426. @dir etc/swanctl/x509aa
  427. @dir etc/swanctl/x509ac
  428. @dir etc/swanctl/x509ca
  429. @dir etc/swanctl/x509crl
  430. @dir etc/swanctl/x509ocsp
  431. @comment @dir etc/ipsec.d/aacerts
  432. @comment @dir etc/ipsec.d/acerts
  433. @comment @dir etc/ipsec.d/cacerts
  434. @comment @dir etc/ipsec.d/certs
  435. @comment @dir etc/ipsec.d/crls
  436. @comment @dir etc/ipsec.d/ocspcerts
  437. @comment @dir etc/ipsec.d/private
  438. @comment @dir etc/ipsec.d/reqs
  439. @owner
  440. @group
  441. @mode
Collapse this list.
USE_RC_SUBR (Service Scripts)
  • strongswan
Dependency lines:
  • strongswan>0:security/strongswan
To install the port:
cd /usr/ports/security/strongswan/ && make install clean
To add the package, run one of these commands:
  • pkg install security/strongswan
  • pkg install strongswan
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: strongswan
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1780929769 SHA256 (strongswan-6.0.7.tar.bz2) = e518e34e159514f4c6ba80d1f926cb151e0dd4e3a1d94213171234b8b9ae6f55 SIZE (strongswan-6.0.7.tar.bz2) = 4939164

Packages (timestamps in pop-ups are UTC):
strongswan
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest6.0.5_16.0.65.9.16.0.16.0.6n/an/an/a
FreeBSD:13:quarterly6.0.56.0.65.9.10_16.0.16.0.6n/an/an/a
FreeBSD:14:latest6.0.76.0.75.9.8_16.0.16.0.7_15.9.10_1-5.9.10_1
FreeBSD:14:quarterly6.0.76.0.7-6.0.16.0.75.9.135.9.135.9.13
FreeBSD:15:latest6.0.76.0.7n/a6.0.1n/an/a5.9.135.9.13
FreeBSD:15:quarterly6.0.76.0.7n/a-n/an/a--
FreeBSD:16:latest6.0.76.0.7n/a-n/an/a--
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. pkgconf>=1.3.0_1 : devel/pkgconf
Library dependencies:
  1. libcurl.so : ftp/curl
There are no ports dependent upon this port

Configuration Options:
===> The following configuration options are available for strongswan-6.0.7: CTR=off: Enable CTR cipher mode wrapper plugin CURL=on: Enable CURL to fetch CRL/OCSP DHCP=off: Enable DHCP based attribute provider plugin EAPAKA3GPP2=off: Enable EAP AKA with 3gpp2 backend EAPDYNAMIC=off: Enable EAP dynamic proxy module EAPRADIUS=off: Enable EAP Radius proxy authentication EAPSIMFILE=off: Enable EAP SIM with file backend FARP=off: Enable farp plugin FIPS_PRF=off: Enable FIPS PRF software implementation plugin GCM=on: Enable GCM AEAD wrapper crypto plugin IKEV1=on: Enable IKEv1 support IPSECKEY=off: Enable authentication with IPSECKEY resource records with DNSSEC KDF=on: Enable KDF (prf+) implementation plugin KERNELLIBIPSEC=off: Enable IPSec userland backend LDAP=off: LDAP protocol support LOADTESTER=off: Enable load testing plugin MEDIATION=off: Enable IKEv2 Mediation Extension ML=on: Enable Module-Lattice-based crypto plugin MYSQL=off: MySQL database support PKCS11=off: Enable PKCS11 token support PKI=on: Enable PKI tools PYTHON=off: Python VICI protocol plugin SMP=off: Enable XML-based management protocol (DEPRECATED) SQLITE=off: SQLite database support STROKE=off: Enable stroke management protcol (DEPRECATED) SWANCTL=on: Install swanctl (requires VICI) TESTVECTOR=off: Enable crypto test vectors TPM=off: Enable TPM plugin TSS2=off: Enable TPM 2.0 TSS2 library UNBOUND=off: Enable DNSSEC-enabled resolver UNITY=off: Enable Cisco Unity extension plugin VICI=on: Enable VICI management protocol XAUTH=off: Enable XAuth password verification ====> Options available for the single PRINTF_HOOKS: you have to select exactly one of them BUILTIN=on: Use builtin printf hooks LIBC=off: Use libc printf hooks VSTR=off: Use devel/vstr printf hooks ===> Use 'make config' to modify these settings
Options name:
security_strongswan
USES:
cpe libtool:keepla pkgconfig ssl tar:bzip2
pkg-message:
For install:
The default strongSwan configuration interface have been updated to vici since version 5.9.2_1. To use the stroke interface by default either compile the port without the vici option or set 'strongswan_interface="stroke"' in your rc.conf file.
If upgrading from > 5.9.2_1:
The default strongSwan configuration interface have been updated to vici. To use the stroke interface by default either compile the port without the vici option or set 'strongswan_interface="stroke"' in your rc.conf file.
Master Sites:
Expand this list (2 items)
Collapse this list.
  1. https://download.strongswan.org/
  2. https://download2.strongswan.org/
Collapse this list.

Number of commits found: 4

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
6.0.7
08 Jun 2026 15:23:45
commit hash: 5a5c70704ff3171b109e9ef588ca8ac13979b6d2commit hash: 5a5c70704ff3171b109e9ef588ca8ac13979b6d2commit hash: 5a5c70704ff3171b109e9ef588ca8ac13979b6d2commit hash: 5a5c70704ff3171b109e9ef588ca8ac13979b6d2 files touched by this commit
R. Christian McDonald (rcm) search for other commits by this committer
security/strongswan: Update 6.0.6 => 6.0.7

Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.0.7

PR:		295936
Approved by:	blanket (fix CVE)
MFH:		2026Q2
Security:	CVE-2026-47895
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit ab71842ed8cd8c3fa1e45093fc22e3efb05ccd9a)
6.0.6
23 Apr 2026 17:25:00
commit hash: 186b8ab13a7750c9902d6bb7e742630867b8673dcommit hash: 186b8ab13a7750c9902d6bb7e742630867b8673dcommit hash: 186b8ab13a7750c9902d6bb7e742630867b8673dcommit hash: 186b8ab13a7750c9902d6bb7e742630867b8673d files touched by this commit This port version is marked as vulnerable.
Vladimir Druzenko (vvd) search for other commits by this committer
security/strongswan: Update 6.0.5 => 6.0.6 (fix 7 CVEs)

Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.0.6

PR:		294718
Approved by:	blanket (fix CVEs)
Security:	CVE-2026-35328
Security:	CVE-2026-35329
Security:	CVE-2026-35330
Security:	CVE-2026-35331
Security:	CVE-2026-35332
Security:	CVE-2026-35333
Security:	CVE-2026-35334
Sponsored by:	UNIS Labs
MFH:		2026Q2

(cherry picked from commit 3b628bd6b80f25100a96ba921c45c6d9e5878061)
6.0.5_1
23 Apr 2026 17:24:54
commit hash: bc430ff70e2d9b47a2eefcddcf5d43ac8eb0d8dccommit hash: bc430ff70e2d9b47a2eefcddcf5d43ac8eb0d8dccommit hash: bc430ff70e2d9b47a2eefcddcf5d43ac8eb0d8dccommit hash: bc430ff70e2d9b47a2eefcddcf5d43ac8eb0d8dc files touched by this commit This port version is marked as vulnerable.
Vladimir Druzenko (vvd) search for other commits by this committer
Author: Mike Bressem
security/strongswan: Enable ML plugin by default to allow Post-Quantum Key
Exchange Methods

Currently ML-DSA (used for Digital Signatures) is a draft in strongswan
(ETA Version 6.1.0 or later). So CNSA 2.0 cannot be fully supported yet.
https://linux-ipsec.org/slides/2025/steffen-pqc-auth-for-ikev2.pdf
But most firewalls (Palo Alto / Fortigate) already support ML-KEM Key
Exchange in addition to standard proposals.
E.g. aes128gcm16-ecp256-ke1_mlkem512.

More details:
https://docs.strongswan.org/docs/latest/config/proposals.html

PR:		294305
Approved by:	strongswan@Nanoteq.com (maintainer, timeout 2 weeks)
Sponsored by:	UNIS Labs

(cherry picked from commit fb347f77757066e2bc0989fd66c8f02c9bf862d9)
6.0.5
06 Apr 2026 22:47:03
commit hash: 6ef9481671f2f4ceb594804abf722df97e9fa9b0commit hash: 6ef9481671f2f4ceb594804abf722df97e9fa9b0commit hash: 6ef9481671f2f4ceb594804abf722df97e9fa9b0commit hash: 6ef9481671f2f4ceb594804abf722df97e9fa9b0 files touched by this commit This port version is marked as vulnerable.
Vladimir Druzenko (vvd) search for other commits by this committer
security/strongswan: Update 6.0.4 => 6.0.5 (CVE-2026-25075)

Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.0.5

While here:
- Switch from post-install + "if PORT_OPTIONS:MVICI" to
  post-install-VICI-on.
- Add option FIPS_PRF - software implementation plugin.
- Improve plist.
- Refresh patches.

Reported by:	Mike Bressem <mike@bressem.com> (via email)
Approved by:	blanket (fix CVE)
Security:	CVE-2026-25075
Sponsored by:	UNIS Labs
MFH:		2026Q2

(cherry picked from commit 2d6221ae7df33419e639c439a12c78fdea84e748)

Number of commits found: 4