GobyVPN

A standards-based IKEv2 VPN client for Windows and macOS — a full userspace IKE and ESP stack.

Windows & macOS Version 1.9.0
RFC 2408/2409 · ISAKMP/IKEv1 RFC 3947/3948 · IKEv1 NAT-T RFC 7296 · IKEv2 RFC 4303 · ESP RFC 4106 · AES-GCM ESP RFC 7383 · IKEv2 Fragmentation RFC 7427 · Digital Signature Auth

What it is

GobyVPN speaks IKEv2 end to end against any conforming headend — PSK, client certificates, or EAP — plus a legacy IKEv1 Aggressive Mode client for gateways that still require it. Both the control plane and the data plane are implemented natively, running over a real virtual network adapter, so it negotiates configurations that platform-native VPN clients often refuse.

Protocol support

IKEv2 (RFC 7296) with ESP, NAT traversal, message fragmentation, and digital-signature authentication, alongside an IKEv1 Aggressive Mode client with XAUTH and Mode Config for older headends.

Flexible authentication

Pre-shared key, client certificates from a file, the platform keystore, or a hardware security token, and EAP — including credentials backed by Touch ID/Secure Enclave and YubiKey PIV.

Cross-platform

A native client on both Windows and macOS, with platform-appropriate privilege separation, virtual adapter handling, routing, and DNS configuration on each.

Session reliability

Automatic re-keying of long-lived tunnels, dead-peer detection, and bounded automatic reconnection after a network interruption.

Fleet-friendly

A bundled default profile that auto-provisions on first launch, so a configuration dropped alongside the installed app reaches every machine without per-user setup.

Everyday usability

A profile manager, live connection status and throughput, a system tray presence, and an advanced view into the active session's negotiated parameters and rekey timers.


Platforms & protocols

One client, the same profile format, across both desktop platforms.

Windows macOS IKEv2 IKEv1 Aggressive Mode PSK Client certificates (RSA / ECDSA) EAP-GTC XAUTH Hardware tokens (YubiKey PIV)

Version history

A summary of what changed in each release. See the in-app About dialog for the exact build you're running.

1.9.0 Latest
  • Reliability improvement: a simplified, more predictable connection lifecycle — a session that reaches a limit now disconnects cleanly instead of renewing silently in the background
  • Added configurable automatic reconnection after a dropped connection
  • Improved fault detection for legacy connections
1.8.0
  • Protocol support: configurable session lifetime negotiation for legacy connections
1.7.1
  • Reliability fix: correct handling of gateway-assigned session lifetime for legacy connections
1.7.0
  • UI improvements: clearer credential editing and an abortable connection attempt
  • Minor dialog-behavior fix
1.6.0
  • UI improvement: a detailed view of the active connection's session parameters and rekey status
1.5.3
  • Fleet-deployment support: automatic provisioning of a bundled default configuration
  • Security: obfuscated credential storage inside configuration files
  • Minor UI polish
1.5.2
  • Reliability fixes to the data plane and automatic reconnection logic
1.5.1
  • Protocol support: added legacy IKEv1 Aggressive Mode connectivity
  • Reliability fixes to logging and connection-negotiation handling
1.4.0
  • UI improvements to profile editing and management
  • Security: configurable trust handling for certificate validity windows
  • Product identity and packaging refresh
1.3.0
  • Reliability improvements for long-lived connections and automatic session renewal
  • Packaging improvements for macOS
1.2.0
  • General stability and reliability improvements across the data plane and platform layer
1.1.0
  • Platform support: added macOS
  • Protocol support: additional authentication methods
  • Security: encrypted local credential storage
1.0.0
  • Initial release: standards-based IKEv2 VPN client for Windows