{"repo":"jawj/IKEv2-setup","free":true,"listed":false,"github":"https://github.com/jawj/IKEv2-setup","clone":"git clone https://github.com/jawj/IKEv2-setup.git","description":"Set up a fresh Ubuntu Server install as an IKEv2 VPN server","language":"Shell","stars":1433,"topics":["ikev2","strongswan","ikev2-vpn","vpn-server","vpn","letsencrypt","ubuntu"],"license":null,"category":"networking-infra","readme_excerpt":"IKEv2-setup See also: https://github.com/jawj/wireguard-setup Table of contents What? + VPN server + VPN clients + Caveats How? + Troubleshooting + Users + Upgrades + Bonus paranoia Why? + Why IKEv2? + Why not Algo? What? A Bash script that takes Ubuntu Server LTS versions 18.04 - 24.04 from clean install to fully-configured IKEv2 VPN using strongSwan. Comments and pull requests welcome. VPN server The VPN server identifies itself with a Let's Encrypt certificate, so there's no need for clients to install private certificates — they can simply authenticate with a username and strong password (EAP-MSCHAPv2). The preferred cipher set is the US Commercial National Security Algorithm Suite (CNSA): aes256gcm16-prfsha384-ecp384 . However, due to an apparent bug in recent versions of macOS, aes256gcm16-prfsha256-ecp256 is also accepted. The box is firewalled with iptables and configured for unattended security upgrades, and the Let's Encrypt certificate is set up to auto-renew, so it could be safe to forget about it all until your chosen Ubuntu version reaches end-of-life. (Note that iptables setup includes basic rate-limiting, dropping new connections if there have been 60+ connection attempts in the last 5 minutes). VPN clients The VPN is tested working with: macOS 10.12 – 14, iOS 10 – 17 — Built-in clients. A .mobileconfig profile is generated for iOS, to set up secure ciphers and enable Connect on demand support. An AppleScript script is generated for Mac, to prompt for VPN cred","default_branch":null,"files":null,"tree":[],"storefront":"/r/jawj","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/jawj/IKEv2-setup/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}