Configuring a secure, roadwarrior-style IKEv2 IPsec VPN using StrongSwan allows a client behind a residential NAT router (such as a standard home DSL/Cable modem) to establish an encrypted tunnel to a remote dedicated server.
1. Server Configuration (/etc/ipsec.conf)
Define the IKEv2 connection on the server. The server listens on its public IP, provisions virtual IPs to clients from 10.10.3.0/24, and routes default internet traffic:
conn win7
left=SERVER.IP.ADD.RESS
leftcert=server.cert
leftid=@server.domain.com
leftsubnet=0.0.0.0/0
right=%any
rightsourceip=10.10.3.0/24
keyexchange=ikev2
auto=add
leftfirewall=yes
2. Client Configuration (/etc/ipsec.conf)
On the client machine behind NAT, set left=%defaultroute and request an IP dynamically from the server via leftsourceip=%config:
conn ike
left=%defaultroute
leftsourceip=%config
leftcert=client.cert
leftid=@client.domain.com
leftfirewall=yes
right=SERVER.IP.ADD.RESS
rightsubnet=0.0.0.0/0
rightid=@server.domain.com
auto=add
3. Initiating the Connection
Start the IPsec tunnel from the client:
ipsec up ike
Check the status to verify security associations (SAs):
ipsec statusall