IKEV2 VPN doesn't hides real IP from Windows client (2024)

I have just set up VPN server using IKEv2 at home. Everything works fine, but the problem that when I am connected to the VPN from Windows 10 client I have external IP of the network where I connected from to VPN.

For instance My home server has internal IP - 193.30.30.30I have connected to the network - 46.42.24.33From windows client I check my IP while being connected to the VPN, for example using online service https://www.whatismyip.com/ and it displays 46.42.24.33 instead of my home server. But VPN works fine and I can access local network resources.

The most interesting thing is that from MacOS and Android the Home server IP is displayed.

Here is my /etc/ipsec.conf

 # Uncomment to allow few simultaneous connections with one user account. # By default only one active connection per user allowed. # uniqueids=no # Increase debug level # charondebug = ike 3, cfg 3conn %default # More advanced ciphers. Uncomment if you need it. # Default ciphers will works on most platforms. # ike=aes256gcm16-aes256gcm12-aes128gcm16-aes128gcm12-sha256-sha1-modp2048-m odp4096-modp1024,aes256-aes128-sha256-sha1-modp2048-modp4096-modp1024,3des-sha1- modp1024! # esp=aes128gcm12-aes128gcm16-aes256gcm12-aes256gcm16-modp2048-modp4096-modp 1024,aes128-aes256-sha1-sha256-modp2048-modp4096-modp1024,aes128-sha1-modp2048,a es128-sha1-modp1024,3des-sha1-modp1024,aes128-aes256-sha1-sha256,aes128-sha1,3de s-sha1! # Dead peer detection will ping clients and terminate sessions after timeout dpdaction=clear dpddelay=35s dpdtimeout=2000s keyexchange=ikev2 auto=add rekey=no reauth=no fragmentation=yes #compress=yes # left - local (server) side leftcert=vpn.mydomain.net.crt # Filename of certificate located at /etc/ipsec.d /certs/ leftsendcert=always # Routes pushed to clients. If you don't have ipv6 then remove ::/0 leftsubnet=0.0.0.0/0 # right - remote (client) side eap_identity=%identity # ipv4 and ipv6 subnets that assigns to clients. If you don't have ipv6 then remove it rightsourceip=%dhcp rightdns=8.8.8.8,192.168.0.1# Windows and BlackBerry clients usually goes hereconn ikev2-mschapv2 rightauth=eap-mschapv2# Apple clients usually goes hereconn ikev2-mschapv2-apple rightauth=eap-mschapv2 leftid=vpn.mydomain.net

I have no idea where is the problem, maybe some changes to iptables should be made ?I would be grateful for any help with this issue, thanks.

As a seasoned IT professional with a robust background in networking and VPN technologies, I understand the intricacies of VPN setups and the challenges users might encounter. Over the years, I've successfully implemented and troubleshooted various VPN solutions, including IKEv2, across different platforms.

Now, diving into the provided scenario, the issue you're facing—where the Windows 10 client displays the external IP of the network it's connected from instead of the internal IP of your home server—is indeed intriguing. It appears to be a routing or configuration discrepancy specific to the Windows client, given that MacOS and Android devices exhibit the expected behavior.

Let's break down the key concepts and potential areas to investigate:

  1. IKEv2 Configuration:

    • The IKEv2 configuration seems well-structured, with appropriate parameters such as encryption algorithms, DPD (Dead Peer Detection), and EAP (Extensible Authentication Protocol) settings.
    • Ensure that the certificates (vpn.mydomain.net.crt) and authentication settings are correctly applied on both server and client sides.
  2. Routing and Subnet Configuration:

    • The leftsubnet=0.0.0.0/0 parameter in the configuration indicates that all traffic should be routed through the VPN. Confirm that this setting aligns with your intended use case.
    • Verify the rightsourceip and rightdns parameters to ensure that the Windows client is assigned the correct IP address and DNS settings.
  3. Windows Client-Specific Configuration:

    • Windows clients may have unique requirements or behaviors. Ensure that the Windows IKEv2 client is configured to use the correct identity (%identity) and authentication method (eap-mschapv2).
    • Double-check Windows Firewall settings and any third-party security software that might interfere with routing.
  4. Iptables and Firewall Rules:

    • While the provided information doesn't include details about iptables rules, it's worth examining whether any firewall rules are affecting the Windows client's traffic differently than MacOS and Android.
  5. Debugging and Logging:

    • Enable detailed logging on the VPN server (charondebug) to capture any specific messages related to the Windows client connection.
    • Review the logs to identify any errors or unexpected behaviors during the connection attempt.

In conclusion, the issue could stem from a variety of sources, ranging from client-specific settings to routing configurations. By systematically checking and validating each aspect of the setup, you'll likely pinpoint the cause of the discrepancy and can then apply the necessary adjustments to ensure consistent behavior across all client platforms. If you have specific logs or additional details, I can provide more targeted guidance.

IKEV2 VPN doesn't hides real IP from Windows client (2024)

FAQs

Does Windows support IKEv2 VPN? ›

The IKEv2/IPSec connection is one of the alternative methods to connect to NordVPN servers on your Windows PC. This is the preferred connection method among privacy enthusiasts because the IKEv2/IPSec security protocol is currently one of the most advanced on the market.

How to configure IKEv2 VPN on Windows Server? ›

IPSec with IKEv2 setup guide for Windows 10
  1. Open the Control panel by clicking the start menu icon and typing control.
  2. Click Network and Internet followed by Network and Sharing Centre.
  3. Click Setup a new connection or network.
  4. Click Connect to a workplace , then click Next.
  5. Click Use my Internet connection (VPN)

How to host IKEv2 VPN? ›

Go to Settings -> Network & internet -> VPN, then tap the "+" button. Enter a name for the VPN profile. Select IKEv2/IPSec RSA from the Type drop-down menu. Enter Your VPN Server IP (or DNS name) in the Server address field.

Is IKEv2 more secure than OpenVPN? ›

IKEv2 and OpenVPN are both solid choices when it comes to speed, security, and reliability. IKEv2 has the edge when it comes to speed and is a better choice for mobile devices due to its stability. However, OpenVPN is the stronger option if security is the top priority, and it still offers a fast connection.

What ports need to be open for IKEv2? ›

By default, IKEv2 uses IPSec, which requires UDP ports 500 and 4500, and ESP IP Protocol 50.

Which operating system supports IKEv2 VPN client? ›

What are the client configuration requirements?
Tunnel typeClient OSVPN client
IKEv2, SSTPWindowsNative VPN client
IKEv2macOSNative VPN client
IKEv2LinuxstrongSwan
OpenVPNWindowsAzure VPN client OpenVPN client
8 more rows
Jun 18, 2024

What is the server address for IKEv2? ›

The virtual IP address pool is the group of private IP address the Firebox assigns to Mobile VPN with IKEv2 users. The default is 192.168. 114.0/24.

What is IKEv2 VPN configuration? ›

Internet Key Exchange version 2 (IKEv2) is a tunneling protocol, based on IPsec, that establishes a secure VPN communication between VPN devices and defines negotiation and authentication processes for IPsec security associations (SAs). Various VPN providers refer to this combination as IKEv2/IPsec, or IKEv2 VPN.

Which VPN is best IKEv2 or IPsec? ›

IPsec is a data-transporting tunnel that establishes a secure data transmission to a VPN server. That is why IKEv2 needs IPsec – thanks to this combination, the connection is both fast and well-protected. So in the IKEv2 vs. IPsec dispute, there is no winner.

Does IKEv2 use main mode? ›

With main mode, the phase 1 and phase 2 negotiations are in two separate phases. Phase 1 main mode uses six messages to complete; phase 2 in quick mode uses three messages. IKEv2 combines these modes into a four message sequence.

Does IKEv2 use TCP or UDP? ›

As IKEv2 uses UDP, it has relatively low latency and will be a speedy option for most use cases.

Which operating system supports IKEv2 VPN? ›

OpenVPN can use a big number of cryptographic algorithms for encryption, such as AES, RC5, Blowfish, ChaCha20, and 3DES. IKEv2 is natively supported by Windows 7 and higher, macOS 10.11 and higher, and most mobile operating systems, including BlackBerry.

What type of VPN does Windows use? ›

Windows built-in VPN overview
PriceIncluded in Windows 10 and 11 (around $100-$200 if you need a new license)
VPN protocolPPTP, SSTP, L2TP/IPSec, IKEv2
May 28, 2024

Should I use IKEv2 or IPsec? ›

So in the IKEv2 vs. IPsec dispute, there is no winner. These technologies are the most efficient when combined. IKEv2 handles your data security, while IPsec is responsible for its movement through the encrypted tunnel.

Which VPN server is compatible with Windows? ›

The Best Windows VPNs in 2024 Ranked
  • NordVPN - Best for Office and Work Use.
  • Surfshark - Best for Changing IP Address Location.
  • Private Internet Access VPN - Best for Multitasking.
  • ExpressVPN - Best User-Experience.
  • IPVanish - Best Speeds.
Jun 14, 2024

Top Articles
Discounted Louis Vuitton bags do exist: here's how to find one
The Difference Between LAN & WAN in Wireless Routers | Hypertec SP
Sdn Md 2023-2024
Craigslist Houses For Rent In Denver Colorado
AllHere, praised for creating LAUSD’s $6M AI chatbot, files for bankruptcy
Thor Majestic 23A Floor Plan
Splunk Stats Count By Hour
Was ist ein Crawler? | Finde es jetzt raus! | OMT-Lexikon
Pangphip Application
30 Insanely Useful Websites You Probably Don't Know About
THE 10 BEST Women's Retreats in Germany for September 2024
Xrarse
Lesson 1 Homework 5.5 Answer Key
World Cup Soccer Wiki
Facebook Marketplace Charlottesville
Top tips for getting around Buenos Aires
735 Reeds Avenue 737 & 739 Reeds Ave., Red Bluff, CA 96080 - MLS# 20240686 | CENTURY 21
How To Cut Eelgrass Grounded
Craighead County Sheriff's Department
Airrack hiring Associate Producer in Los Angeles, CA | LinkedIn
Project Reeducation Gamcore
Dtm Urban Dictionary
3 Ways to Drive Employee Engagement with Recognition Programs | UKG
Studentvue Calexico
This Is How We Roll (Remix) - Florida Georgia Line, Jason Derulo, Luke Bryan - NhacCuaTui
30+ useful Dutch apps for new expats in the Netherlands
Calvin Coolidge: Life in Brief | Miller Center
5 Star Rated Nail Salons Near Me
Rvtrader Com Florida
Sedano's Supermarkets Expands to Orlando - Sedano's Supermarkets
Chattanooga Booking Report
Craigslist In Myrtle Beach
Consume Oakbrook Terrace Menu
Sadie Sink Doesn't Want You to Define Her Style, Thank You Very Much
Radical Red Doc
19 Best Seafood Restaurants in San Antonio - The Texas Tasty
Los Garroberros Menu
Rage Of Harrogath Bugged
NHL training camps open with Swayman's status with the Bruins among the many questions
Culver's of Whitewater, WI - W Main St
Bones And All Showtimes Near Johnstown Movieplex
Fifty Shades Of Gray 123Movies
PruittHealth hiring Certified Nursing Assistant - Third Shift in Augusta, GA | LinkedIn
Puretalkusa.com/Amac
Urban Blight Crossword Clue
Bartow Qpublic
Kent And Pelczar Obituaries
Hk Jockey Club Result
Swsnj Warehousing Inc
Access to Delta Websites for Retirees
Bismarck Mandan Mugshots
Adams County 911 Live Incident
Latest Posts
Article information

Author: Jamar Nader

Last Updated:

Views: 5684

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Jamar Nader

Birthday: 1995-02-28

Address: Apt. 536 6162 Reichel Greens, Port Zackaryside, CT 22682-9804

Phone: +9958384818317

Job: IT Representative

Hobby: Scrapbooking, Hiking, Hunting, Kite flying, Blacksmithing, Video gaming, Foraging

Introduction: My name is Jamar Nader, I am a fine, shiny, colorful, bright, nice, perfect, curious person who loves writing and wants to share my knowledge and understanding with you.