* It inherits strong, modern crypto from Trevor Perrin's Noise Protocol Framework.
* It's designed to be extremely simple to configure for the common case.
* It has a microscopic trusted code base --- 4-5000 lines compared with hundreds of thousands for strongSwan --- and the protocol was specifically designed to enable that; for instance, the protocol makes specific allowances to enable implementations without any dynamic allocation.
* It's probably the fastest available VPN.
You can only use it on Linux at the moment, but that will change this year.
WireGuard is so good people at my company spin up Vagrant images on their Macbooks to use it. Check it out:
Benjamin Dowling and Kenny Paterson (a name you might be familiar with) just completed and published a formal analysis of WireGuard; the results are complicated (the eCK model WireGuard was proven under doesn't contemplate separate key exchange and data transport phases) but here's a TLDR from Kenny: