strongSwan VPN Client app icon

strongSwan VPN Client

An easy to use IKEv2/IPsec-based VPN client.

Psiphon Inc. · org.strongswan.android

3.5 out of 5 (4 ratings) 1M+ downloads v2.3.3 7.6 MB Android 4.0.3+ PEGI 3 · Everyone

  • Signature matches the Google Play version Details

At a glance

Latest version
v2.3.3 (75)
Updated
Jul 1, 2026 (3 months ago)
APK size
7.6 MB
Requires
Android 4.0.3+ (API 15)
CPU support
x86 32-bit, x86 64-bit, ARM 32-bit, ARM 64-bit
Category
Communication (app)
Listed since
Mar 6, 2021 (at least)
Permissions
6 (2 sensitive)
Website
wiki.strongswan.org/projects/strongswan/wiki/AndroidVPNClient
Developer contact
[email protected]
Privacy
Developer's privacy policy

About this APK

strongSwan VPN Client is an app by Psiphon Inc. in the Communication category, listed since at least March 2021. It includes native code for x86 32-bit, x86 64-bit, ARM 32-bit and ARM 64-bit, so it runs on practically every phone.

It asks for 6 permissions, 2 of them sensitive: read shared storage and see all installed apps.

What's new in v2.3.3

# 2.3.3 # - Adds a button to install user certificates # 2.3.2 # - Don't mark VPN connections as metered (the default changed when targeting Android 10 with the last release) # 2.3.1 # - Optionally use IPv6 transport addresses for IKE and ESP. Can only be enabled if the server supports UDP encapsulation for IPv6 (the Linux kernel only supports this since 5.8, so many servers will not support it yet)

Description

From the listing uploaded by “appupdater”.

Official Android port of the popular strongSwan VPN solution. # FEATURES AND LIMITATIONS # * Uses the VpnService API featured by Android 4+. Devices by some manufacturers seem to lack support for this - strongSwan VPN Client won't work on these devices! * Uses the IKEv2 key exchange protocol (IKEv1 is not supported) * Uses IPsec for data traffic (L2TP is not supported) * Full support for changed connectivity and mobility through MOBIKE (or reauthentication) * Supports username/password EAP authentication (namely EAP-MSCHAPv2, EAP-MD5 and EAP-GTC) as well as RSA/ECDSA private key/certificate authentication to authenticate users, EAP-TLS with client certificates is also supported * Combined RSA/ECDSA and EAP authentication is supported by using two authentication rounds as defined in RFC 4739 * VPN server certificates are verified against the CA certificates pre-installed or installed by the user on the system. The CA or server certificates used to authenticate the server can also be imported directly into the app. * IKEv2 fragmentation is supported if the VPN server supports it (strongSwan does so since 5.2.1) * Split-tunneling allows sending only certain traffic through the VPN and/or excluding specific traffic from it * Per-app VPN allows limiting the VPN connection to specific apps, or exclude them from using it * The IPsec implementation currently supports the AES-CBC, AES-GCM, ChaCha20/Poly1305 and SHA1/SHA2 algorithms * Passwords are currently stored as cleartext in the database (only if stored with a profile) * VPN profiles may be imported from files Details and a changelog can be found on our wiki: https://wiki.strongswan.org/projects/strongswan/wiki/AndroidVPNClient # PERMISSIONS # * READ_EXTERNAL_STORAGE: Allows importing VPN profiles and CA certificates from external storage on some Android versions * QUERY_ALL_PACKAGES: Required on Android 11+ to select apps to ex-/include in VPN profiles and the optional EAP-TNC use case # EXAMPLE SERVER CONFIGURATION # Example server configurations may be found on our wiki: https://wiki.strongswan.org/projects/strongswan/wiki/AndroidVPNClient#Server-Configuration Please note that the host name (or IP address) configured with a VPN profile in the app *must be* contained in the server certificate as subjectAltName extension. # FEEDBACK # Please post bug reports and feature requests via GitHub: https://github.com/strongswan/strongswan/issues/new/choose If you do so, please include information about your device (manufacturer, model, OS version etc.). The log file written by the key exchange service can be sent directly from within the application.

Security & authenticity

Security rating: Trusted

Signing certificate

  • Signature matches the Google Play version Checked by the source store on Jul 1, 2026.
  • Certificate issued to “strongSwan Project” This is the certificate of the Google Play version.

Store checks and file details

  • Developer signature verified Jul 1, 2026
  • Validated against Google Play Jul 1, 2026
  • Signed byCN=strongSwan Project
  • Signing certificate (SHA-1)4A:FC:13:31:F9:08:6D:0C:0B:FB:E1:88:A6:AD:94:0B:CC:4F:A8:6F
  • File MD575510aad0cbe85778f8d4699c6950726
  • Uploaded by “appupdater” Gold tier · 117,810 followers · uploading since 2020

Scans and ratings come from the source store; the certificate comparisons are AAPKs's own, made from the files' published signatures. AAPKs doesn't scan files itself — compare the MD5 and signer after downloading.

Permissions (6)

strongSwan VPN Client requests 6 permissions, 2 of them sensitive.

Required hardware & features

strongSwan VPN Client APK: questions and answers

Can I install this APK over the version I already have?

Yes, if your installed copy is older. It is signed like the Google Play version, so Android installs it as an update and keeps your data.

Is the strongSwan VPN Client APK safe?

No one can promise that a file is safe, but some things can be checked. The source store rates this file Trusted. Its signature matches the Google Play version. After downloading, check that the file's MD5 is 75510aad0cbe85778f8d4699c6950726.

Tags

More Communication apps