Skip to content

IKEv2 on Linux with strongSwan (NetworkManager)

Desktop Linux speaks IKEv2 through strongSwan, and the friendliest way to drive it is its NetworkManager plugin: the VPN appears in Settings and in the menu in the top right, next to your other connections. We ran every step below on Ubuntu 24.04; other GNOME desktops look the same.

One setting people miss

With default options the connection authenticates and then fails at the tunnel stage with FAILED_CP_REQUIRED / TS_UNACCEPT. The fix is a single checkbox, Request an inner IP address, covered in step 4. If you’re here because of that error, jump straight to it.

What you need

From your IKEv2 page (log in first):

  • Your VPN username and password (top card; separate from your website login)
  • A server address from the IKEv2 page

Setup Guide

  1. Install the strongSwan NetworkManager plugin

    Terminal window
    sudo apt update && sudo apt install network-manager-strongswan libcharon-extra-plugins

    On Ubuntu 24.04 the new VPN type is there right away. If it doesn’t show up on your system, log out and back in.

  2. Add the VPN connection

    Open Settings → Network, select + next to VPN, and choose IPsec/IKEv2 (strongswan).

    Add VPN in Ubuntu Settings, listing OpenVPN, PPTP, IPsec/IKEv2 (strongswan), WireGuard and Import from file
  3. Fill in the server and your login

    On the Identity tab:

    • Name: anything you like, for example VPNBaron London
    • Address: the server address from the IKEv2 page
    • Certificate: leave as (None); the server presents a public certificate
    • Authentication: EAP (Username/Password), already selected
    • Username: your VPN username from the IKEv2 page
    • Password: the box starts greyed out. Select the icon at its right end, choose Store the password only for this user, then type your VPN password.
  4. Tick “Request an inner IP address”

    In the Options section at the bottom, tick Request an inner IP address. It starts unticked, and without it the server turns the tunnel down right after you sign in.

    The Identity tab of the IKEv2 connection: server address, EAP authentication, username and password filled in, and Request an inner IP address ticked
  5. Add and connect

    Select Add, then switch the VPN on.

    Ubuntu Settings, Network, with the VPNBaron London IKEv2 connection switched on

    From now on you can switch it on and off from the menu in the top right.

    Ubuntu's top-right menu with the VPN tile switched on for VPNBaron London

Verify

From a terminal:

Terminal window
curl -s https://api.ipify.org
resolvectl dns

The first should print the VPN server’s address, not yours. The second lists the DNS servers: the VPN’s own resolver appears on the VPN interface (its name starts with nm-xfrm), so your lookups go through the tunnel. IKEv2 is a fast native protocol, so on a good line it barely dents your speed. Here’s a real result through the tunnel on a UK server:

Speedtest result through the VPNBaron IKEv2 tunnel: 747 Mbps down, 259 Mbps up

Troubleshooting

Headless server instead?

Without a desktop, strongSwan is configured via swanctl.conf, which is its own rabbit hole. For servers we recommend VPNBaron CLI or the OpenVPN command line, or open a ticket and we’ll help with a swanctl config.