SwanDesk
A native macOS menu-bar VPN client for strongSwan IPsec — IKEv2 and IKEv1, every authentication method, as many simultaneous tunnels as you need, with your secrets kept in the Keychain.
Download for macOS
A native macOS menu-bar VPN client for strongSwan IPsec — IKEv2 and IKEv1, every authentication method, as many simultaneous tunnels as you need, with your secrets kept in the Keychain.
Download for macOSSwanDesk puts strongSwan IPsec tunnels behind a simple menu-bar icon: a glance tells you the connection state, one click connects or disconnects, and a configuration window exposes every VPN parameter across as many named profiles as you need — connected one at a time or all at once. It bundles its own strongSwan, OpenSSL and dnsmasq, so there is nothing to install from Homebrew — and nothing at runtime to keep up to date.
Connect to strongSwan and other IPsec gateways over either IKE version, chosen per profile. IKE and ESP proposals are configured with structured Encryption, Integrity and DH Group pickers — or raw strongSwan syntax for advanced use.
Certificate + XAuth, pure certificate, the IKEv2 EAP methods EAP-MSCHAPv2 and EAP-TLS, and pre-shared key — including PSK with the gateway verified by certificate, or fully mutual PSK. Credentials can be stored in the Keychain or prompted at connect time.
Connect several profiles simultaneously — each gets its own tunnel inside a single strongSwan daemon. Drag profiles to set their priority: when tunnels claim overlapping routes or DNS, the one higher in the list wins, and a lower one takes over automatically if it drops.
Enable it per profile and, if the VPN unexpectedly disconnects or stops working, all network traffic is blocked so nothing leaks outside the tunnel — while SwanDesk keeps reconnecting in the background. Traffic is unblocked the moment you disconnect yourself.
A green / red / amber status dot, one-click connect and disconnect, and multiple named profiles — with selected ones connecting automatically when SwanDesk launches. Tunnels survive the menu closing and are torn down cleanly on quit; an emergency Forcibly Stop & Kill menu item nukes every VPN process and restores your network in one go.
Export a profile to an encrypted .swandesk file — the full config plus
secrets sealed with PBKDF2-HMAC-SHA256 and AES-256-GCM — and import it on another Mac
without exposing a thing.
A bundled dnsmasq instance runs on 127.0.0.1:53 during the tunnel, routing per-domain queries to the VPN’s resolvers while leaving all other traffic on the regular nameservers. A free-form dnsmasq config block per profile gives full control over forwarding rules, local overrides and more — and with several tunnels up, the highest-priority profile’s configuration drives the resolver.
SwanDesk bundles and links strongSwan and dnsmasq, both licensed under the GNU General Public License version 2, together with OpenSSL under the Apache License 2.0. In accordance with the GPL, the complete corresponding source for SwanDesk is available below.
strongSwan, dnsmasq and OpenSSL are bundled as unmodified upstream releases. For at least three years from the date you received this software, Juvex Oy will provide a complete machine-readable copy of their corresponding source on request — .