# hwdsl2/setup-ipsec-vpn: an IPsec VPN server on Ubuntu in one command

> The repository installs Libreswan and xl2tpd on a Linux server and hands back working IPsec/L2TP, Cisco IPsec and IKEv2 credentials. It is a server-side installer, not a client, and it wants a machine you are willing to dedicate.

**hwdsl2/setup-ipsec-vpn** — Set up your own IPsec VPN server in just a few minutes, with IPsec/L2TP, Cisco IPsec and IKEv2. Supports Ubuntu, Debian, CentOS/RHEL, Alpine Linux and Raspberry Pi OS. Includes client config and management scripts.

- Repository: https://github.com/hwdsl2/setup-ipsec-vpn
- Stars: 28,503 · Forks: 6,514
- Language: Shell
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/hwdsl2-setup-ipsec-vpn

## What problem the installer removes

Standing up an IPsec server by hand means configuring Libreswan, wiring xl2tpd on top of it for L2TP, generating certificates for IKEv2, and then producing client profiles that iOS, macOS and Android will actually accept. Each of those pieces has its own configuration syntax, and the failure modes are quiet: a mismatched PSK or a missing NAT traversal setting shows up as a client that simply never connects. The repository's stated purpose is to collapse that into one command. The README describes the result as a fully automated setup with no user input needed, using Libreswan as the IPsec server and xl2tpd as the L2TP provider. The intended user is someone with a cloud server, VPS or dedicated server who wants their own endpoint rather than a commercial VPN subscription. The README is explicit that these scripts are for servers only and warns against running them on a PC or Mac.

## How the scripts and the two daemons fit together

The repository is a set of shell scripts rather than a long-running service. At the top level sit vpnsetup.sh plus distribution-specific variants including vpnsetup_ubuntu.sh, vpnsetup_centos.sh, vpnsetup_alpine.sh and vpnsetup_amzn.sh, which is how one project covers Ubuntu, Debian, CentOS Stream, Rocky, AlmaLinux, Oracle Linux, Alpine, Kali and Raspberry Pi OS without a single branching script. The main script installs and configures Libreswan for IKEv2 and Cisco IPsec, then configures xl2tpd as the L2TP provider layered on the same IPsec stack. Credentials are generated or supplied at install time, and the README says the generated login details are displayed when the script finishes. The repository also ships helper scripts under extras/ for managing VPN users and certificates, which matters because adding or revoking a user after install should not mean re-running the whole installer. Client-side profiles are generated so that iOS, macOS and Android devices can auto-configure rather than being typed in by hand.

## Installing on Ubuntu and making the first connection

The README's quick start assumes a supported OS is already installed on the server. The one-liner downloads the script and runs it as root. The README notes that login details are randomly generated and printed at the end.

```bash
wget https://get.vpnsetup.net -O vpn.sh && sudo sh vpn.sh
```

If wget is unavailable, the README gives a curl equivalent with the same output file name.

```bash
curl -fsSL https://get.vpnsetup.net -o vpn.sh && sudo sh vpn.sh
```

To choose your own credentials instead of accepting generated ones, the README's second option is to download the script, edit it, and then run it. It names the three values to replace as YOUR_IPSEC_PSK, YOUR_USERNAME and YOUR_PASSWORD, and notes that a secure IPsec PSK should be at least 20 random characters.

```bash
wget https://get.vpnsetup.net -O vpn.sh
nano -w vpn.sh
sudo sh vpn.sh
```

A third option defines the same credentials as environment variables, with the README warning that all values must be placed inside single quotes. On servers with an external firewall, such as EC2 or GCE, the README says to open UDP ports 500 and 4500 for the VPN. After the script completes, the printed credentials and the generated profiles are what you feed to the client device.

## Where the installer stops being the right tool

The most obvious limitation is stated by the project itself: this is server-side software. If what you want is a client that connects to someone else's endpoint, nothing here helps you. The second constraint is the network path. IPsec needs UDP 500 and 4500 reachable, and the README calls this out specifically for servers behind an external firewall. On a network where you cannot open those ports, the install will succeed and the tunnel will not come up, which is a confusing failure because the script reports success. Third, the licence file is present as LICENSE.md but the repository metadata reports the licence as NOASSERTION, so the actual terms are not something the README states in plain language; anyone embedding this in a product should read LICENSE.md directly rather than assume. Finally, the README does not document an uninstall or rollback procedure. The scripts configure system daemons and firewall rules on a machine you may be using for other things, and there is no described path back to the prior state.

## Compared with WireGuard and OpenVPN installers

The same author maintains separate installers for WireGuard, OpenVPN and Headscale, and the README points at them as options that can be installed on the same server. The difference is protocol design, not packaging. WireGuard is a much smaller codebase with a simpler key model, and its installer workflow is correspondingly shorter; IPsec, by contrast, is what your laptop, phone and router already speak natively. That is the real argument for this project over the WireGuard installer: on iOS, macOS, Android and Windows you configure a built-in IPsec client rather than installing anything, and the README leans on this by listing Windows, macOS, iOS, Android, Chrome OS and Linux as supported clients. The cost is that IPsec carries more configuration surface, which is exactly the surface these scripts exist to hide. If your clients can install software freely, the WireGuard route is less machinery. If they cannot, IPsec is the pragmatic choice.

## Maintenance, upgrades and licence questions

The repository is not archived and the last push was on 2026-09-08, so the project is being touched recently. That matters less than it sounds, because the components doing the work are Libreswan and xl2tpd, both external. Upgrading the server OS can move those packages underneath a configuration the script wrote, and the README's installation section recommends updating and rebooting the server before installing, which reduces but does not remove that risk. There are no retrieved releases, so there is no versioned artefact to pin; the install path pulls a script from a URL, and the README offers GitHub and GitLab raw URLs as alternatives if the primary download fails. That is a supply-chain consideration worth naming: you are executing a script fetched over the network as root. The README also offers a pre-built Docker image in a separate repository for anyone who would rather not run the script directly on the host. On licensing, LICENSE.md exists at the repository root, but the metadata label is NOASSERTION, so treat the file itself as the source of truth and get your own reading of it before redistributing anything.

## Conclusion

Adopt it if you already rent a VPS and want a self-hosted IPsec endpoint for iOS, macOS, Android, Windows, Chrome OS or Linux clients without hand-editing Libreswan configuration. Do not adopt it if you need a client, if your server sits behind a firewall you cannot open UDP 500 and 4500 on, or if you expected the script to be reversible. Before running it, confirm your distribution appears in the requirements list, that you have console access in case the tunnel breaks your SSH session, and that you have read the credential options in the script, because the README does not document a rollback path.

## FAQ

### How to set up an IPsec VPN with hwdsl2/setup-ipsec-vpn?

Prepare a server running a supported OS, then run the one-liner from the README, wget https://get.vpnsetup.net -O vpn.sh && sudo sh vpn.sh, which installs and configures the server and prints randomly generated login details when it finishes.

### What is an IPsec VPN?

The README describes it as a VPN that encrypts your network traffic so nobody between you and the server can eavesdrop as the data travels over the Internet, which it says is especially useful on unsecured networks such as coffee shops, airports or hotel rooms.

### Is there a free IPsec VPN available?

The scripts themselves are published in this repository and can be run on a server you already have, so there is no software licence fee described in the README. The server itself is not free: the README expects a cloud server, VPS or dedicated server, and points to providers such as DigitalOcean, Vultr, Linode, OVH and Microsoft Azure.

### How to check if IPsec is enabled?

The README does not describe a specific verification command. What it does say is that the script displays your VPN login details when it finishes, and that on servers with an external firewall you must open UDP ports 500 and 4500 for the VPN to work.

### How to set up an IPsec VPN on Windows 10?

The README lists Windows among the supported VPN clients and says the setup generates VPN profiles to auto-configure iOS, macOS and Android devices. It does not give Windows-specific client steps, so the credentials printed at the end of the install are what you enter into the built-in Windows VPN client.

### How to set up an IPsec VPN on an iPhone?

The README lists iOS as a supported client and states that the setup generates VPN profiles to auto-configure iOS, macOS and Android devices, so an iPhone can be configured from the generated profile rather than by entering every setting by hand.

## Sources

- [hwdsl2/setup-ipsec-vpn on GitHub](https://github.com/hwdsl2/setup-ipsec-vpn)
- [Issues](https://github.com/hwdsl2/setup-ipsec-vpn/issues)
- [README](https://github.com/hwdsl2/setup-ipsec-vpn/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/hwdsl2-setup-ipsec-vpn
