This document describes how to connect to a VPN Relay Server of VPN Gate by using the L2TP/IPsec VPN Client which is bundled with the operating system.
L2TP/IPsec VPN Client is built-in on Windows, Mac, iOS and Android. It is easier to configure thanusing OpenVPN. L2TP/IPsec VPN is recommended before you try to use OpenVPN. However, some networks or firewalls block L2TP/IPsec packets. If L2TP/IPsec fails, try OpenVPN.
Connecting parameters for L2TP/IPsec VPN
You can quickly configure your L2TP/IPsec VPN Client by using the following parameters if you have already known how to set up.
- IP Address / Hostname: You can obtain them in Public VPN Relay Servers List page.
Username: vpn, Password: vpn
Pre-shared Key (Secret): vpn
Select your OS
- Windows
- Mac
- iPhone / iPad
- Android
VPN on Windows step by step guide (Using L2TP/IPsec VPN)
Here is the instruction how to connect to a VPN Gate Public VPN Relay Server by using L2TP/IPsec VPN Client which is built-in on Windows XP, 7, 8, 10, RT, Server 2003, 2008 and 2012.
- SoftEther VPN Client is recommended on Windows.
L2TP/IPsec Client configurations are difficult than SoftEther VPN Client.
If you are using Windows, using SoftEther VPN Client is recommended because it is very easy to configure and stable. SoftEther VPN Client can show the list of currently running VPN Gate Servers on the software screen.
On this instruction, we use Windows 7 screens. Windows XP and Windows 8 are similar, however there are a little number of changes.
1. Initial configurations (only once at the first time)
Right-click the network icon on the bottom-right side of Windows screen, and click "Open Network and Sharing Center" .
Click "Set up a new connection or network" on the "Network Sharing Center" .
Select "Connect to a workplace" .
Select "Use my Internet connection (VPN)" .
Open the VPN Servers List page and choose a VPN Server which you want to connect.
Copy the DDNS Hostname (an identifier ends with ".opengw.net" ) or IP Address (digits as xxx.xxx.xxx.xxx) and paste it on the "Internet address" field on the configuration wizard.
- In general, DDNS Hostname (an identifier ends with ".opengw.net" ) are recommended to specify. DDNS hostname can continue to be used even if the corresponding IP address of the DDNS hostname will change in future. However, in some countries or regions, you might be unable to use DDNS hostname. If you fails to specify a DDNS hostname, try IP Address (digits as xxx.xxx.xxx.xxx) specification instead.
After you paste the "Internet address" , check "Don't connect now; just set up so I can connect later" checkbox on the bottom of the screen surely.
If the username and password prompting screen appears, input "vpn" (3-letters) on both username and password field. You should check "Remember this password" .
When "The connection is ready to use" message appears, click the "Close" button. Do not click the "Connect now" button.
Go to "Network and Sharing Center" and click "Change adapter settings" .
The currently defined VPN connection settings are listed. Right click the icon you created in the previous step, and click "Properties" .
On the Properties screen, switch to the "Security" tab. (In Windows XP, switch to the "Network" tab.) Choose "Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec)" on the "Type of VPN" drop-down list.
Next, click the "Advanced settings" button. (In Windows XP, click the "IPsec Settings" on the "Security" tab.)
The following screen will appear. Click "Use preshared key for authentication" and input "vpn" (3-letters) on the "Key" field.
After the above configuration finished, click the "OK" button twice to close the property screen of the VPN connection setting.
2. Connect to the VPN Server
Double-click the created VPN connection setting, the below screen will appear.
"User name" and "Password" fields should be filled automatically if you enable password-saving options in previous steps. If not, input "vpn" on both "User name" and "Password" fields.
Click the "Connect" button to start the VPN connecting attempts.
While the VPN is trying to be established, the following screen displays statuses. If an error occurs, confirm your settings make sure that the type of VPN is "L2TP/IPsec" , and the pre-shared key is correctly specified.
If the VPN connection is successfully established, a VPN connection icon will be listed on the screen which appears when you click the network icon on the bottom-right of Windows screen. The status of the VPN connection icon should be "Connected" .
By the way, you can initiate the VPN connection by simply clicking this VPN icon from now on.
3. Enjoy Internet via VPN relaying
While VPN is established, all communications towards the Internet will be relayed via the VPN Server. You can verify that by using "tracert 8.8.8.8" command on the Windows Command Prompt.
As the above figure, if the packet-path are through "10.211.254.254" , your communication is now relayed via one of VPN Gate Public VPN Servers.
You can also visit the VPN Gate Top Page to see your current global IP address. You can see your source country or region has been changed to other if you are connecting to a VPN server which is located on oversea country.
Enjoy YouTube, Facebook or Twitter while your VPN connection is established.
Facebook, Twitter and Gmail uses HTTPS (SSL) encrypted communication protocols. Regardless of VPN or non-VPN, no one can tap these encrypted communications.
VPN on Mac step by step guide (Using L2TP/IPsec VPN)
Here is an instruction how to connect to a VPN Gate Public VPN Relay Server by using L2TP/IPsec VPN Client which is built-in on Mac OS X.
On this instruction, every screen-shots are taken on Mac OS X Mountain Lion. Other versions of Mac OS X are similar to be configured, however there might be minor different on UIs.
These screen-shots are in English version of Mac OS X. If you use other language, you can still configure it easily by referring the following instructions.
1. Initial configurations (only once at the first time)
Click the network icon on the top-right side on the Mac screen. Click "Open Network Preferences..." in the menu.
Click the "+" button on the network configuration screen.
Select "VPN" as "Interface" , "L2TP over IPsec" as "VPN Type" and click the "Create" button.
A new L2TP VPN configuration will be created, and the configuration screen will appear.
On this screen, you have to specify either hostname or IP address of the destination VPN Gate Public VPN Relay Server.
Open the VPN Servers List page, and click one VPN Relay Server which you want to use. Copy the DDNS Hostname (an identifier ends with ".opengw.net" ) or IP Address (digits as xxx.xxx.xxx.xxx) and paste it on the "Server Address" field on the configuration screen.
- In general, DDNS Hostname (an identifier ends with ".opengw.net" ) are recommended to specify. DDNS hostname can continue to be used even if the corresponding IP address of the DDNS hostname will change in future. However, in some countries or regions, you might be unable to use DDNS hostname. If you fails to specify a DDNS hostname, try IP Address (digits as xxx.xxx.xxx.xxx) specification instead.
After you specified the "Server Address" , input "vpn" (3-letters) on the "Account Name" field, which is the next to the "Server Address" field.
Next, click the "Authentication Settings..." button.
The authentication screen will appear. Input "vpn" (3-letters) to the "Password" field. Specify "vpn" (3-letters) also on the"Shared Secret" field. After you input them, click the "OK" button.
After return to the previous screen, check the "Show VPN status in menu bar" and click the "Advanced..." button.
The advanced settings will be appeared. Check the "Send all traffic over VPN connection" and click the "OK" button.
On the VPN connection settings screen, click the "Connect" button to start the VPN connection.
2. Start a VPN connection
You can start a new VPN connection by clicking the"Connect" button at any time. You can also initiate a VPN connection by clicking the VPN icon on the menu bar.
After the VPN connection will be established, the VPN connection setting screen will become as below as the "Status" will be "Connected" . Your private IP address on the VPN, and connect duration time will be displayed on the screen.
3. Enjoy Internet via VPN relaying
While VPN is established, all communications towards the Internet will be relayed via the VPN Server.
You can visit the VPN Gate Top Page to see your current global IP address. You can see your source country or region has been changed to other if you are connecting to a VPN server which is located on oversea country.
Enjoy YouTube, Facebook or Twitter while your VPN connection is established.
Facebook, Twitter and Gmail uses HTTPS (SSL) encrypted communication protocols. Regardless of VPN or non-VPN, no one can tap these encrypted communications.
VPN on iPhone / iPad step by step guide (Using L2TP/IPsec VPN)
Here is an instruction how to connect to a VPN Gate Public VPN Relay Server by using L2TP/IPsec VPN Client which is built-in on iPhone / iPad.
On this instruction, every screen-shots are taken on iOS 6. Other versions of iOS are similar to be configured, however there might be minor different on UIs.
These screen-shots are in English version of iOS. If you use other language, you can still configure it easily by referring the following instructions.
1. Initial configurations (only once at the first time)
From the iOS main screen, start the "Settings" application.
Open "VPN" in "General" , and tap "Add VPN Configuration..." .
A new L2TP VPN connection setting will be created, and the configuration screen will appear.
On this screen, you have to specify either hostname or IP address of the destination VPN Gate Public VPN Relay Server.
Open the VPN Servers List page, and click one VPN Relay Server which you want to use. Copy the DDNS Hostname (an identifier ends with ".opengw.net" ) or IP Address (digits as xxx.xxx.xxx.xxx) and paste it on the "Server" field on the configuration screen.
- In general, DDNS Hostname (an identifier ends with ".opengw.net" ) are recommended to specify. DDNS hostname can continue to be used even if the corresponding IP address of the DDNS hostname will change in future. However, in some countries or regions, you might be unable to use DDNS hostname. If you fails to specify a DDNS hostname, try IP Address (digits as xxx.xxx.xxx.xxx) specification instead.
After you specify the "Server" field, you have to input "vpn" (3-letters) to "Account" , "Password" and "Secret" fields. After input, tap "Save" .
2. Connect a VPN
You can start a VPN connection by using a created VPN connection setting at any time.
Tap the "OFF" button to initiate a VPN connection.
While VPN is established, you can see the status and connect time on the status screen. Your private IP address in VPN is also displayed. The "Connect to" IP address reports "1.0.0.1" , but it is not an unusual.
3. Enjoy Internet via VPN relaying
While VPN is established, all communications towards the Internet will be relayed via the VPN Server.
You can visit the VPN Gate Top Page to see your current global IP address. You can see your source country or region has been changed to other if you are connecting to a VPN server which is located on oversea country.
iOS displays the "VPN" indicator on the top bar of the screen while VPN is established.
Enjoy YouTube, Facebook or Twitter while your VPN connection is established.
Facebook, Twitter and Gmail uses HTTPS (SSL) encrypted communication protocols. Regardless of VPN or non-VPN, no one can tap these encrypted communications.
VPN on Android step by step guide (Using L2TP/IPsec VPN)
Here is an instruction how to connect to a VPN Gate Public VPN Relay Server by using L2TP/IPsec VPN Client which is built-in on Android.
On this instruction, every screen-shots are taken on Android 4.x. Other versions of Android 4.x are similar to be configured, however there might be minor different on UIs. Some third-parties customizes the configuration screens of Android.
These screen-shots are in English version Android iOS. If you use other language, you can still configure it easily by referring the following instructions.
1. Initial configurations (only once at the first time)
Start the "Settings" application on Android.
In the "Wireless & Networks" category, open"More..." and tap "VPN".
Click the "Add VPN profile" button to create a new VPN connection setting.
A new VPN connection setting editing screen will appear. Input something string on the "Name" field (e.g. "vpn" ), and choose "L2TP/IPSec PSK" in the "Type" field.
On this screen, you have to specify either hostname or IP address of the destination VPN Gate Public VPN Relay Server.
Open the VPN Servers List page, and click one VPN Relay Server which you want to use. Copy the DDNS Hostname (an identifier ends with ".opengw.net" ) or IP Address (digits as xxx.xxx.xxx.xxx) and paste it on the "Server address" field on the configuration screen.
- In general, DDNS Hostname (an identifier ends with ".opengw.net" ) are recommended to specify. DDNS hostname can continue to be used even if the corresponding IP address of the DDNS hostname will change in future. However, in some countries or regions, you might be unable to use DDNS hostname. If you fails to specify a DDNS hostname, try IP Address (digits as xxx.xxx.xxx.xxx) specification instead.
Scroll down the configuration screen, and tap the "Show advanced options" checkbox if appropriate.
Specify "vpn" (3-letters) on the "IPSec pre-shared key" field.
Specify "0.0.0.0/0" (9-letters) on the"Forwarding routes" field. Make sure that you input the "Forwarding routes" field correctly. If not, you cannot communicate via VPN.
After all inputted, tap the "Save" button and save the VPN connection setting.
2. Connect a VPN
You can start a VPN connection by using a created VPN connection setting at any time. Open the VPN connection settings list and tap a setting, you will see the following screen.
At the first time of using, you have to input "Username" and "Password" fields.
Specify "vpn" (3-letters) on both "Username" and "Password" fields, and check "Save account information" .
Tap "Connect" to start the VPN connection.
After the VPN connection will be established, the indicate string "Connected" will be displayed next to the VPN connection setting, and the status indication area of Android will show "VPN activated" message. You can tap the message to see the current status of the VPN connection.
3. Enjoy Internet via VPN relaying
While VPN is established, all communications towards the Internet will be relayed via the VPN Server.
You can visit the VPN Gate Top Page to see your current global IP address. You can see your source country or region has been changed to other if you are connecting to a VPN server which is located on oversea country.
Enjoy YouTube, Facebook or Twitter while your VPN connection is established.
Facebook, Twitter and Gmail uses HTTPS (SSL) encrypted communication protocols. Regardless of VPN or non-VPN, no one can tap these encrypted communications.
Any errors using L2TP/IPsec VPN?
- Username, password and pre-shared key are all "vpn" (3-letters). Especially, make sure you input the pre-shared key correctly.
- Mac OS X and Android needs a special settings to make the VPN server relays all traffics. Confirm the above instructions again.
- Make sure that the destination hostname or IP address are correct, viewing the VPN Servers List page.
- In some countries or regions, specifying DDNS Hostname (.opengw.net) might fail. In such an environment, specify the IP address directly instead of DDNS hostname.
- Your local firewall might filter any L2TP/IPsec packets. In such a network, L2TP cannot be used. If you use Windows, try Using SoftEther VPN Client. Mac, iOS or Android, tryUsing OpenVPN.
FAQs
How do I connect to IPSec L2TP? ›
On the 'VPN' screen, add a new entry. Specify the name, connection type 'L2TP/IPSec PSK', the server address is the public IP address of the router or its KeenDNS domain name, and enter the preshared IPSec key previously installed on the VPN server. Save the connection settings. Click on the created connection.
How does L2TP IPSec VPN Work? ›L2TP is a networking protocol used by the ISPs to enable VPN operations. IPsec. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session.
How do I fix the problem of Windows 10 not connecting to IPSec L2TP VPN servers? ›- Ensure that the Required L2TP/IPsec Ports are enabled on VPN Server's side. ...
- Connect to VPN via another device or network. ...
- Delete and recreate the VPN connection.
- Step 1: Update System. ...
- Step 2: Install Remote Access Role. ...
- Step 3: Configure Routing and Remote Access. ...
- Step 4: Configure VPN Properties. ...
- Step 5: Configure NAT. ...
- Step 6: Restart Routing and Remote Access. ...
- Step 7: Configure Windows Firewall. ...
- Step 8: Create VPN User.
- Method 1: Uninstall latest security updates.
- Method 2: Turn on the Microsoft CHAP v2 Protocol.
- Method 3: Turn on the LCP Protocol Extensions.
- Method 4: By Restarting IPSec Service.
- Method 5: By Reinstalling the Network Adapter.
The L2TP protocol can be highly secure when used in conjunction with IPSec. It is highly compatible, working on operating systems like Windows and macOS by default. L2TP (and L2TP/IPSec) are relatively easy to set up due to their high compatibility. More firewall-friendly as it runs over UDP protocol.
What are the authentication methods for L2TP and IPSec? ›With L2TP/IPsec, the user authentication process is encrypted using the Data Encryption Standard (DES) or Triple DES (3DES) algorithm. L2TP/IPsec using IKEv1 requires two levels of authentication: Computer-level authentication with a preshared key to create the IPsec SAs to protect the L2TP-encapsulated data.
Is L2TP VPN good? ›L2TP on its own is unsafe: This protocol can achieve fast speeds, however, those speeds come at the cost of having no means of encryption or authentication. L2TP/IPSec is slower due to the double encapsulation feature: This option encapsulates data twice, which increases its toll on device resources.
Why does L2TP connection attempt fail? ›"The L2TP connection attempt failed because the security layer encountered a processing error during the initial negotiations with the remote computer."
What is a L2TP internet connection? ›Layer Two Tunneling Protocol (L2TP) is an extension of the Point-to-Point Tunneling Protocol (PPTP) used by internet service providers (ISPs) to enable virtual private networks (VPNs). To ensure security and privacy, L2TP must rely on an encryption protocol to pass within the tunnel.
What ports need to be open for L2TP VPN? ›
By default, L2TP uses IPSec, which requires UDP ports 500 and 4500, and ESP IP Protocol 50. If you disable IPSec, Mobile VPN with L2TP requires only UDP port 1701.
How do I fix L2TP VPN on Windows 10? ›- Right-click the Start button and go to Network Connections.
- Click VPN on the left side.
- Select your L2TP VPN connection and click Advanced options.
- Press Edit.
- Retype your User name and Password.
- Click Save.
- In the Windows notification area (System Tray), click the Network icon. A list of available networks and VPNs appears.
- Click the VPN connection. The Network & Internet VPN settings appear.
- Select the VPN connection. Click Connect. ...
- Type your user name and password.
- Click OK.
If your VPN software is not working properly, you can do several things: check your network settings, change your server, make sure the right ports are opened, disable the firewall, and reinstall your VPN software. If none of the below methods are working, it's time to contact your VPN provider.
How do I test my L2TP connection? ›Right-click the Dialup Networking folder, and then click Properties. Click the Networking tab, and then click to select the Record a log file for this connection check box.
Is L2TP better than IPSec? ›Really both will work and provide similar characteristics. Pure IPSec with IPSec tunnelling provides a little more efficiency while IPSec/L2TP can carry multiple protocols (other than IP for example). It all depends on the choice of protocol and the architecture of the endpoints.
How do I connect to IPSec VPN? ›Enter Your VPN Username for the Account Name. Click the Authentication Settings button. In the User Authentication section, select the Password radio button and enter Your VPN Password . In the Machine Authentication section, select Shared Secret and enter Your VPN IPsec PSK .
Should I enable L2TP pass through? ›If your VPN connection relies on old VPN protocols such as PPTP and L2TP, you should. These protocols do not play well with NAT. Routers use NAT to know how to map and route packets on network devices. However, if you are using a modern VPN connection, there's no need to enable the VPN passthrough.
Why is my VPN authentication failed? ›There are a few reasons you may encounter a VPN authentication error, including: Your antivirus software or firewall is blocking your connection. The VPN server is too slow to connect. Your VPN software download is corrupted or out of date.
Which Layer 3 protocols can be transmitted over and L2TP VPN? ›Which layer 3 protocols can be transmitted over a L2TP VPN? Explanation: Data roming layer.
Which type of VPN is best? ›
ExpressVPN is currently the fastest VPN we've tested in 2022, causing us to lose less than 2% of our total internet speeds. Its apps for iOS and Android are designed with a streamlined approach aimed at connecting fast without a fuss.
What's the best type of VPN? ›OpenVPN is the most often recommended, and widely used VPN protocol. It's fast, secure, and open source, so it can be vetted and improved by third-parties. The only real downside is the difficulty in setup and configuration. Failing to set it up the right way could lead to security holes and lackluster performance.
What is required for VPN connection? ›To get started, you'll need a VPN client, a VPN server, and a VPN router. The downloadable client connects you to servers around the world, so employees everywhere can access your small business network. The client can be used on devices like smartphones and laptops, even if workers are using public Wi-Fi networks.
Which 3 protocols are used by VPN? ›- PPTP. Point-to-Point Tunneling Protocol is one of the oldest VPN protocols in existence. ...
- L2TP/IPSec. Layer 2 Tunnel Protocol is a replacement of the PPTP VPN protocol. ...
- OpenVPN. OpenVPN is an open source protocol that allows developers access to its underlying code. ...
- SSTP. ...
- IKEv2.
- IP AH. AH is specified in RFC 4302. ...
- IP ESP. Specified in RFC 4303, ESP provides authentication, integrity and confidentiality through encryption of IP packets.
- IKE. ...
- Internet Security Association and Key Management Protocol (ISAKMP).
In addition to older and less-secure password-based authentication methods (which should be avoided), the built-in VPN solution uses Extensible Authentication Protocol (EAP) to provide secure authentication using both user name and password, and certificate-based methods.
Is L2TP secure without IPsec? ›It is common to carry PPP sessions within an L2TP tunnel. L2TP does not provide confidentiality or strong authentication by itself. IPsec is often used to secure L2TP packets by providing confidentiality, authentication and integrity.
Which VPN protocol is best for speed? ›WireGuard is considered to the fastest VPN protocol, offering quicker connection/reconnection times and improved battery life for mobile devices. NordLynx by NordVPN couples WireGuard's speed with enhanced security. IKEv2/IPsec is also considered a fast protocol and it may serve the needs of many.
What is Server address L2TP? ›Layer 2 Tunneling Protocol (L2TP) is a VPN tunneling protocol that allows remote clients to use the public IP network to securely communicate with private corporate network servers. L2TP uses PPP over UDP (port 1701) to tunnel the data. L2TP protocol is based on the client and server model.
Does L2TP require certificates? ›A valid computer certificate and root certificate are required on both VPN client and VPN server.
How do I access IPsec VPN? ›
- Establish a VPN connection to the private network through SSL or IPsec.
- Access your server by using its private 10. x.x.x IP address through SSH or RDP.
- Connect to your server's IPMI IP address for additional server management or rescue needs.
Enter Your VPN Username for the Account Name. Click the Authentication Settings button. In the User Authentication section, select the Password radio button and enter Your VPN Password . In the Machine Authentication section, select Shared Secret and enter Your VPN IPsec PSK .
How do I enable IPsec connection? ›- Open platcfg. See Accessing platcfg.
- Select Network Configuration.
- Select IPsec Configuration.
- Select IPsec Connections.
- Select Edit.
- Select Connection Control.
- Select the IPsec connection to enable or disable.
- Select Enable or Disable.
- Login management page of the router and go to Advanced -> Network -> Internet.
- Choose PPTP as Internet Connection Type.
- Input the correct Username and Password.
- Input the correct VPN Server IP/Domain Name. ...
- Please click Save and then Connect.
- Open your phone's Settings app.
- Tap Network & internet. VPN. If you can't find it, search for "VPN." If you still can't find it, get help from your device manufacturer.
- Tap the VPN you want.
- Enter your username and password.
- Tap Connect. If you use a VPN app, the app opens.
Check your welcome email: When you sign up for a VPN service, you should receive a welcome email from the provider. This email will contain all the information you need to connect to the VPN, including the server address.
Why the VPN is not connecting? ›If your VPN software is not working properly, you can do several things: check your network settings, change your server, make sure the right ports are opened, disable the firewall, and reinstall your VPN software. If none of the below methods are working, it's time to contact your VPN provider.
Is L2TP VPN secure? ›The L2TP protocol can be highly secure when used in conjunction with IPSec. It is highly compatible, working on operating systems like Windows and macOS by default. L2TP (and L2TP/IPSec) are relatively easy to set up due to their high compatibility. More firewall-friendly as it runs over UDP protocol.
Do all VPNs use IPsec? ›Many VPNs use the IPsec protocol suite to establish and run these encrypted connections. However, not all VPNs use IPsec. Another protocol for VPNs is SSL/TLS, which operates at a different layer in the OSI model than IPsec.
Does L2TP need port forwarding? ›L2TP/IPSec requires UDP 500 and UDP 4500 forwarding. Another option is to forward all ports and protocols, which on some routers is called DMZ. A typical example of such a router is a CDCEthernet modem. It can receive a public address from a mobile operator and assign a private address to the Keenetic router.
How do I get my VPN to automatically connect? ›
On Android
Tap on the Settings icon in the upper-left corner and choose VPN connection. Tap Auto-connect. Select when you want to establish a VPN connection automatically. Tap Auto-connect to and select the server you want to connect automatically.
- From the Windows 10 Start Menu, click Settings.
- Click Network & Internet.
- On the left navigation menu, select VPN.
- Click Add a VPN connection.
- In the VPN provider text box, select Windows (built-in).
- In the Connection name text box, type a name for the Mobile VPN (such as "L2TP VPN")