{"id":187,"date":"2020-09-26T13:15:33","date_gmt":"2020-09-26T13:15:33","guid":{"rendered":"https:\/\/dft.wiki\/?p=187"},"modified":"2026-06-09T15:02:25","modified_gmt":"2026-06-09T19:02:25","slug":"l2tp-ipsec-psk-client-on-ubuntu","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=187","title":{"rendered":"L2TP\/IPSec PSK Client on Ubuntu"},"content":{"rendered":"<p>Ubuntu 18.04 only offers OpenVPN as an available VPN method in the GNOME graphical interface.<\/p>\n<pre>sudo apt-get update<br \/>sudo apt-get install network-manager-l2tp<br \/>sudo apt-get install network-manager-l2tp-gnome<\/pre>\n<p>This will add L2TP support to your Ubuntu network manager and GNOME. Now just follow the steps:<\/p>\n<ol class=\"list\">\n<li>Go to Settings -&gt; Network -&gt; VPN. Click the <strong>[+] button<\/strong>.<\/li>\n<li>Select the Layer 2 Tunneling Protocol (<strong>L2TP<\/strong>).<\/li>\n<li>Enter anything you like in the Name field: <strong>Router VPN<\/strong>\n<ul>\n<li>It can be any name.<\/li>\n<\/ul>\n<\/li>\n<li>Enter your VPN server address in the Gateway field: <em><strong>yourname.duckdns.org<\/strong> or <strong>IP<\/strong>.<\/em>\n<ul>\n<li>If you don&#8217;t have a static IP, it is recommended to use a dynamic DNS service such as DuckDNS [<a href=\"http:\/\/www.duckdns.org\/\">http:\/\/duckdns.org\/<\/a>], which is completely free.<\/li>\n<\/ul>\n<\/li>\n<li>Enter your VPN username in the User name field: <strong><em>username<\/em><\/strong>\n<ul>\n<li>Configure the same user on the server side.<\/li>\n<\/ul>\n<\/li>\n<li>Right-click the <strong>[?] in the Password field<\/strong> and select &#8220;Store the password only for this user&#8221;.<\/li>\n<li>Enter your VPN password in the Password field: <strong><em>*<\/em>******<\/strong>\n<ul>\n<li>Configure the same password on the server side.<\/li>\n<\/ul>\n<\/li>\n<li>Leave the NT Domain field <strong>blank<\/strong>.<\/li>\n<li>Click the <strong>IPsec Settings<\/strong> button.<\/li>\n<li>Check the <strong>Enable IPsec tunnel to L2TP host<\/strong> checkbox.<\/li>\n<li>Leave the Gateway ID field <strong>blank<\/strong>.<\/li>\n<li>Enter your VPN IPsec <strong>PSK<\/strong> in the Pre-shared key field: <strong><em>a2N4uPNl1s3zkiuCEkZrQKhphpoEGlsB<\/em><\/strong>\n<ul>\n<li>This must match what is configured on the server. You can use a random key generator to create one [<a href=\"https:\/\/cloud.google.com\/vpn\/docs\/how-to\/generating-pre-shared-key\">https:\/\/cloud.google.com\/vpn\/docs\/how-to\/generating-pre-shared-key<\/a>].<\/li>\n<\/ul>\n<\/li>\n<li>Expand the <strong>Advanced<\/strong> section.<\/li>\n<li>Enter the <strong>Phase1<\/strong> Algorithms: <strong><em>aes128-sha1-modp2048!<\/em><\/strong><\/li>\n<li>Enter the <strong>Phase2<\/strong> Algorithms: <strong><em>aes128-sha1-modp2048!<\/em><\/strong><\/li>\n<li>Click <strong>OK<\/strong>, then click <strong>Add<\/strong> to save the VPN connection.<\/li>\n<li>Turn the VPN switch <strong>ON<\/strong>.<\/li>\n<\/ol>\n<p>There are other suggestions for Phase1 and Phase2 Algorithms (steps 14 and 15):<\/p>\n<pre>Phase1: aes128-sha1-modp2048,3des-sha1-modp1024<br \/>Phase2: aes128-sha1,3des-md5<br \/><br \/>OR<br \/><br \/>Phase1: aes128-sha1-modp1024,3des-sha1-modp1024!<br \/>Phase2: aes128-sha1,3des-md5<\/pre>\n<p>For more information about IPsec negotiations, see [<a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Fireware\/mvpn\/general\/ipsec_vpn_negotiations_c.html\">https:\/\/www.watchguard.com\/&#8230;\/ipsec_vpn_negotiations_c.html<\/a>].<\/p>\n<p>Your VPN security depends on the strength of your <strong>User\/Password<\/strong>, <strong>Pre-Shared Key<\/strong>, and <strong>Phase1\/2 Algorithms<\/strong>. As always, find a balance between security and performance.<\/p>\n<p>This tutorial also works with the Quick VPN feature on D-Link devices such as the DIR-882 AC2600 [<a href=\"https:\/\/ca.dlink.com\/en\/products\/dir-882-ac2600-high-power-wifi-gigabit-router\">https:\/\/ca.dlink.com\/&#8230;\/dir-882-ac2600<\/a>].<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ubuntu 18.04 only offers OpenVPN as an available VPN method in the GNOME graphical interface. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-187","post","type-post","status-publish","format-standard","hentry","category-linux"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=187"}],"version-history":[{"count":7,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/187\/revisions"}],"predecessor-version":[{"id":5851,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/187\/revisions\/5851"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}