Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    L2tp/ipsec windows 10/7 native clients

    Scheduled Pinned Locked Moved IPsec
    7 Posts 3 Posters 6.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      ptclabs
      last edited by

      After hours and hours of trying different configurations listed in the internet. Is there any setup that will work with Windows native vpn client. I have a client that has some older users that cannot figure out how to use openvpn and it is not worth putting a appliance at their location to have it auto connect. thanks

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        For a native VPN on Windows clients, use IKEv2 not L2TP/IPsec.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • luckman212L
          luckman212 LAYER 8
          last edited by

          What's the most current/accurate (canonical) guide for setting up IKEv2 VPN for road warriors on 2.3.x?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            The ones on the wiki. It depends on what style you need/want.

            https://doc.pfsense.org/index.php/IKEv2_with_EAP-MSCHAPv2
            https://doc.pfsense.org/index.php/IKEv2_with_EAP-RADIUS
            https://doc.pfsense.org/index.php/IKEv2_with_EAP-TLS

            Though depending on the Windows version you might need other client-side adjustments, for example on Windows 10 Anniv. Update you might have to change the setting to send all traffic over the tunnel.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • luckman212L
              luckman212 LAYER 8
              last edited by

              Right, I am well aware of those links. The reason I asked is because last time I tried, I ran into various quirks depending on OS (iPhone, Mac, Win10 client) so I was hoping there was an up-to-date guide that included these extra steps to make it all hum withiut scouring forums.  Admittedly the last time I tried was a few months ago so not sure if much has changed…

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Your original question stated L2TP/IPsec, not IKEv2, so there was no disclosure that you'd known about or tried those. They are the most current public documents but it is possible that operating system updates have rendered parts of them inaccurate.

                The same settings are unlikely to work on Windows and OS X/iOS out of the box, but that's easily solved by getting Windows to work and then using Apple's VPN profile tools to make a profile you can import into OS X / iOS which will work with the same settings as Windows. None of those are pfSense problems though, they're client configuration problems.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • luckman212L
                  luckman212 LAYER 8
                  last edited by

                  OP wasn't mine it was ptclabs, but thanks for the info. I will give it a try again on a fresh config.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.