# jawj/IKEv2-setup

Set up a fresh Ubuntu Server install as an IKEv2 VPN server

Repository: https://github.com/jawj/IKEv2-setup
Canonical: https://ross.abutalabs.com/products/ikev2-setup
Language: Shell
License Family: other
Topics: ikev2, strongswan, ikev2-vpn, vpn-server, vpn, letsencrypt, ubuntu
Last push: 2025-12-02T10:31:18+00:00

## Health v2 (maintenance only)
Score: 57/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 55, release rhythm 35, longevity 100
- inputs: {"age_days": 3932, "days_push": 274, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1433, forks 341 (observed 2026-08-28T04:04:43.284794+00:00)

## What it is
A Bash script that configures a fresh Ubuntu Server LTS install as an IKEv2 VPN server using strongSwan, with Let's Encrypt certificates and CNSA-grade ciphers. It generates client configuration files and instructions for macOS, iOS, Windows, Ubuntu, and Android.

## Use cases
- set up a personal IKEv2 VPN server on Ubuntu
- configure strongSwan VPN with Let's Encrypt certificates
- create VPN client profiles for iOS, macOS, Windows, and Android
- harden a fresh VPS as a secure VPN endpoint
- deploy a VPN server with username/password authentication
- secure a remote server with iptables and automatic security updates

## When to choose
- you want a one-command, opinionated IKEv2 VPN setup on Ubuntu Server 18.04-24.04
- you need native VPN clients on Apple, Windows, and Android devices without installing custom certificates
- you prefer strong CNSA cipher suites and automatic certificate renewal

## When to avoid
- you need IPv6 support, which is deliberately disabled
- you want a multi-cloud or multi-distro tool rather than Ubuntu-specific setup
- you need WireGuard or OpenVPN instead of IKEv2

## Facets
- artifact type: cli-tool
- maturity: active
- function: vpn, security, networking, cryptography, configuration-management, deployment
- domain: security, privacy, networking, self-hosted
- platform: cli, self-hosted
- tags: ikev2, strongswan, lets-encrypt, ubuntu, vpn-server, shell-script, eap-mschapv2, devops, linux

## Member repositories
- jawj/IKEv2-setup (main) score 57

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:43.284794+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:36:57.718650+00:00, confidence not recorded.
  - readme: https://github.com/jawj/IKEv2-setup (fetched 2026-08-28T04:04:43.284794+00:00, sha 535b0ef3c32a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
