VPN Protocols

    IKEv2/IPsec VPN for Mobile Customers

    IKEv2 is the key exchange protocol that sets up IPsec VPN connections. It can be a good fit for phones and other devices that move between networks. It is available in the Windows and macOS VPNclient apps and through manual setup on compatible phones, routers and other clients.

    Pairs with
    IPsec
    Good for
    network changes
    Works on
    apps, phones, routers
    Managed VPN infrastructure
    Included VPNclient apps
    REST API
    Pay only for active accounts
    21+ years in infrastructure

    What Is IKEv2/IPsec?

    IKEv2 (Internet Key Exchange version 2, specified in RFC 7296) negotiates keys and security associations between a device and a VPN server. The traffic itself is then protected by IPsec. That is why the combination is usually written as IKEv2/IPsec.

    MOBIKE (RFC 4555) is an optional IKEv2 extension that lets an existing connection update its address when a device changes networks, for example moving from Wi-Fi to mobile data. It only applies when both the client and the server support and enable it, so it is not an inherent guarantee of IKEv2. How smoothly a connection handles a network change depends on the device, operating system and client configuration.

    Mobility options

    With the optional MOBIKE extension enabled at both ends, a connection can follow a device across networks.

    Native OS support

    Many operating systems include a built-in IKEv2 client for manual setup.

    Standards based

    An IETF standard with IPsec doing the traffic encryption.

    When IKEv2 Is a Good Choice

    • Customers who move between Wi-Fi and mobile data during the day.
    • Devices where a built-in operating system VPN client is preferred over an app.
    • A stable alternative when another protocol drops on a particular network.

    Practical Limitations

    • Seamless switching is not guaranteed in every configuration; it depends on the device and client.
    • IKEv2 uses specific UDP ports, so restrictive networks that block them can prevent connections.
    • Available connection modes can vary by app and version, so customers should check their current app or contact support.

    IKEv2/IPsec Availability

    VPNresellers supports IKEv2/IPsec on the service side. Inside the ready-made apps, IKEv2 is a confirmed mode in the Windows and macOS VPNclient apps. Beyond the apps, IKEv2 can be set up manually on compatible phones, including iPhone and Android devices with an IKEv2-capable client, on routers that support IKEv2, and on other compatible clients. What works on a given device depends on its operating system, client and router capabilities, so customers should check their current app or contact support.

    Download links for every platform are on the white label apps page. Setup help is in the Help Center.

    IKEv2 in a White Label VPN Offering

    IKEv2 gives customers another option in the included Windows and macOS apps, and lets phone users and router owners connect with a compatible built-in or third-party IKEv2 client. The settings needed for manual setup are documented in our Help Center.

    Most resellers present IKEv2 as a reliable alternative rather than the default, with WireGuard first.

    IKEv2/IPsec FAQ

    Is IKEv2 the same as IPsec?

    Not exactly. IKEv2 negotiates the keys and security settings, and IPsec encrypts the traffic. Together they form an IKEv2/IPsec VPN connection.

    Will IKEv2 keep the VPN connected when switching from Wi-Fi to mobile data?

    It can, when the optional MOBIKE extension (RFC 4555) is supported and enabled on both the client and the server. MOBIKE is not an inherent guarantee of IKEv2, and results depend on the device, operating system and configuration.

    Where can customers use IKEv2?

    VPNresellers supports IKEv2/IPsec on the service side. Inside the ready-made apps, IKEv2 is a confirmed mode in the Windows and macOS VPNclient apps. Beyond the apps, IKEv2 can be set up manually on compatible phones, including iPhone and Android devices with an IKEv2-capable client, on routers that support IKEv2, and on other compatible clients. What works on a given device depends on its operating system, client and router capabilities, so customers should check their current app or contact support.

    Where do I find the IKEv2 Remote ID and Local ID?

    They are listed in the Help Center article on IKEv2 Remote ID and Local ID. Customers using the VPNclient apps do not need to enter them.

    Background reading: RFC 7296 (IKEv2) · RFC 4555 (MOBIKE)

    Build with VPNresellers

    Give Mobile and Desktop Customers More Options

    Combine IKEv2 with WireGuard and OpenVPN on managed VPNresellers infrastructure.

    Read the VPNresellers API documentation →