A standards-based IKEv2 VPN client for Windows and macOS — a full userspace IKE and ESP stack.
GobyVPN speaks IKEv2 end to end against any conforming headend — PSK, client certificates, or EAP — plus a legacy IKEv1 Aggressive Mode client for gateways that still require it. Both the control plane and the data plane are implemented natively, running over a real virtual network adapter, so it negotiates configurations that platform-native VPN clients often refuse.
IKEv2 (RFC 7296) with ESP, NAT traversal, message fragmentation, and digital-signature authentication, alongside an IKEv1 Aggressive Mode client with XAUTH and Mode Config for older headends.
Pre-shared key, client certificates from a file, the platform keystore, or a hardware security token, and EAP — including credentials backed by Touch ID/Secure Enclave and YubiKey PIV.
A native client on both Windows and macOS, with platform-appropriate privilege separation, virtual adapter handling, routing, and DNS configuration on each.
Automatic re-keying of long-lived tunnels, dead-peer detection, and bounded automatic reconnection after a network interruption.
A bundled default profile that auto-provisions on first launch, so a configuration dropped alongside the installed app reaches every machine without per-user setup.
A profile manager, live connection status and throughput, a system tray presence, and an advanced view into the active session's negotiated parameters and rekey timers.
One client, the same profile format, across both desktop platforms.
A summary of what changed in each release. See the in-app About dialog for the exact build you're running.