strongSwan Documentation
strongswan.org Downloads GitHub

strongSwan Docs

    • What’s New in strongSwan 6.0
    • Introduction to strongSwan
    • Introduction to IPsec
  • Installation
    • Installation Documentation
    • Autoconf Options
    • Linux Kernel Modules
    • Reduced Privileges
  • Configuration
    • Configuration Quickstart
    • Certificates Quickstart
      • GUI-based CA Management
    • Configuration Files
      • strongswan.conf
      • strongswan.d Directory
      • swanctl.conf
      • swanctl Directory
    • Algorithm Proposals (Cipher Suites)
    • Logging
    • Identity Parsing
    • Job Priority Management
    • Tuning IKE SA Lookup
    • IKE and IPsec SA Renewal
    • Retransmission
    • TLS Options
    • SQLite Database Schema
    • IPv6 and the Neighbor Discovery Protocol
  • Features
    • Virtual IP Addresses
    • MOBIKE
    • NAT Traversal
    • Route-based VPN
    • NetworkManager
    • High Availability
    • Hash and URL
    • IPComp
    • AGGFRAG / IP-TFS
    • Per-CPU SAs
    • Integrity Tests
    • IPsec and Related Standards
  • How-tos
    • Forwarding and Split-Tunneling
    • Security Recommendations
    • Smart Card Configuration
    • Cloud Platforms
    • strongSwan in Linux Network Namespaces
    • Taking Traffic Dumps
  • Daemons
    • charon
    • charon-systemd
    • charon-svc
    • charon-cmd
  • Portability / OS
    • Android
      • Android VPN Client
      • Android VPN Client Profiles
      • Android VPN Privacy Policy
      • Android VPN Client Build
    • Windows
    • FreeBSD
    • macOS
  • Interoperability
    • Windows Clients
      • Windows Certificate Requirements
      • Using Machine Certificates
        • Storing a Windows Machine Certificate
        • Windows Client Configuration with Machine Certificates
        • Windows Client Connection with Machine Certificates
        • strongSwan Configuration for Windows Machine Certificates
        • strongSwan Connection Status with Windows Machine Certificates
      • Using User Certificates
        • Storing a Windows User Certificate
        • Storing a Windows CA Certificate
        • Windows Client Configuration with User Certificates
        • Windows Client Connection with User Certificates
        • strongSwan Configuration for Windows User Certificates
        • strongSwan Connection Status with Windows User Certificates
      • Using EAP
        • Windows Client EAP Configuration with Passwords
        • Windows Client EAP Connection with Passwords
        • strongSwan EAP Configuration with Passwords
        • strongSwan EAP Connection Status with Passwords
      • Microsoft Status Notify
    • iOS and macOS
      • Apple IKEv2 Configuration Profile
    • Fortinet Devices
  • Tools
    • swanctl Tool
      • swanctl --counters
      • swanctl --flush-certs
      • swanctl --initiate
      • swanctl --install
      • swanctl --list-algs
      • swanctl --list-authorities
      • swanctl --list-certs
      • swanctl --list-conns
      • swanctl --list-pols
      • swanctl --list-pools
      • swanctl --list-sas
      • swanctl --load-all
      • swanctl --load-authorities
      • swanctl --load-conns
      • swanctl --load-creds
      • swanctl --load-pools
      • swanctl --log
      • swanctl --redirect
      • swanctl --rekey
      • swanctl --reload-settings
      • swanctl --stats
      • swanctl --terminate
      • swanctl --uninstall
      • swanctl --version
    • pki Tool
      • pki --acert
      • pki --dn
      • pki --est
      • pki --estca
      • pki --gen
      • pki --issue
      • pki --keyid
      • pki --ocsp
      • pki --pkcs12
      • pki --pkcs7
      • pki --print
      • pki --pub
      • pki --req
      • pki --scep
      • pki --scepca
      • pki --self
      • pki --signcrl
      • pki --verify
    • cert-enroll Tool
    • pt-tls-client Tool
    • sw-collector Tool
    • sec-updater Tool
    • ipsec pool Tool
    • ipsec attest Tool
    • ipsec conftest Tool
    • ipsec scepclient Tool
  • Plugins
    • Plugin List
      • addrblock Plugin
      • attr Plugin
      • attr-sql Plugin
      • bypass-lan Plugin
      • certexpire Plugin
      • connmark Plugin
      • constraints Plugin
      • counters Plugin
      • coupling Plugin
      • curl Plugin
      • dhcp Plugin
      • duplicheck Plugin
      • eap-dynamic Plugin
      • eap-gtc Plugin
      • eap-radius Plugin
      • eap-simaka-sql Plugin
      • eap-tls Plugin
      • error-notify Plugin
      • ext-auth Plugin
      • farp Plugin
      • forecast Plugin
      • ha Plugin
      • kernel-iph Plugin
      • kernel-libipsec Plugin
      • kernel-wfp Plugin
      • load-tester Plugin
      • lookip Plugin
      • openxpki Plugin
      • pkcs11 Plugin
      • radattr Plugin
      • resolve Plugin
      • save-keys Plugin
      • selinux Plugin
      • socket-win Plugin
      • sql Plugin
      • systime-fix Plugin
      • test-vectors Plugin
      • tnc-ifmap Plugin
      • tpm Plugin
      • unity Plugin
      • updown Plugin
      • vici Plugin
      • whitelist Plugin
      • winhttp Plugin
      • xauth-eap Plugin
      • xauth-noauth Plugin
      • xauth-pam Plugin
    • Plugin Load Options
  • Development
    • Developer Documentation
    • Contributions
    • Programming Style
    • Object Oriented C
    • Testing Environment
    • Fuzzing
  • Platform Security
    • TPM 2.0
      • TPM 2.0 Use with strongSwan IKE Daemon
    • Trusted Network Connect
      • TNC Client
      • TNC Server
      • Optimum PB-TNC Batch and PA-TNC Message Sizes
      • strongTNC
      • Software Inventory
        • Software Inventory Client
        • Software Inventory Server
      • Measured Boot
        • Attestation Client
        • Attestation Server
        • PCR Boot Events
      • Integrity Measurement Architecture
        • IMA Client
        • IMA Server
  • Support
    • Help Requests
    • FAQ
    • Flaw Reporting
    • Free Support
    • Commercial Support
  • Publications
    • Publications and Presentations
    • strongSwan Blog
strongSwan Docs 6.0
  • strongSwan Docs
    • 6.0
    • 5.9
  • strongSwan Docs
  • IPv6 Configuration Examples
6.0 5.9
Edit this Page

IPv6 Configuration Examples

Site-to-Site

IPv6 in IPv6 tunnel mode

IKEv1

IKEv2

IPv4 in IPv6 tunnel mode

IKEv1

IKEv2

IPv6 in IPv4 tunnel mode

IKEv1

IKEv2

Host-to-Host

IPv6 tunnel mode

IKEv1

IKEv2

IPv6 transport mode

IKEv1

IKEv2

Remote Access

RSA authentication with X.509 certificates

IKEv1

IKEv2

PSK authentication with pre-shared keys

IKEv1

IKEv2

IPv6 in IPv4 tunnel mode with virtual IP

IKEv1

IKEv2

Complete List

  • All IPv6 test scenarios

strongSwan Logo

Copyright © 2021-2025 The strongSwan Team and individual contributors. The content is provided under a CC BY 4.0 license

The UI for this site is derived from the Antora default UI and is licensed under the MPL-2.0 license.