L2TP/IPsec VPN for Legacy Compatibility
L2TP/IPsec is a legacy option that VPNresellers keeps for devices and systems that require it. L2TP builds the tunnel and IPsec provides the encryption. For new setups, we recommend WireGuard or IKEv2.
- Role
- compatibility
- Encryption
- from IPsec
- Recommended instead
- WireGuard or IKEv2
L2TP does not encrypt traffic on its own
L2TP is a tunneling protocol only. In the service VPNresellers provides, L2TP runs inside IPsec, and it is IPsec that protects the traffic. Use L2TP/IPsec only when a device or system cannot use a modern protocol.
What Is L2TP/IPsec?
L2TP (Layer 2 Tunneling Protocol) carries traffic between a device and a VPN server, but it does not provide confidentiality by itself. RFC 3193 describes how to secure L2TP by running it over IPsec, which handles encryption and integrity.
Because L2TP/IPsec is built into many older operating systems and network devices, it can still be useful when nothing more modern is available. It adds an extra layer of encapsulation and is generally less efficient and less flexible than WireGuard or IKEv2.
Tunnel: L2TP
Builds the tunnel that carries the customer's traffic.
Protection: IPsec
Encrypts and authenticates the L2TP traffic.
Use case: legacy
Kept for devices and systems that require it.
When L2TP/IPsec Makes Sense
- Older devices or systems that only offer L2TP/IPsec in their built-in VPN settings.
- Business equipment that cannot run a VPN app.
- Routers or phones whose built-in VPN settings offer L2TP/IPsec but no modern option.
Practical Limitations
- Double encapsulation adds overhead compared with modern protocols.
- Uses fixed ports that restrictive networks often block.
- When a shared secret is used, its security depends on how that secret is managed and on the IPsec and authentication configuration. We recommend WireGuard or IKEv2 for better performance and security.
L2TP/IPsec Availability
VPNresellers supports L2TP/IPsec on the service side. Inside the ready-made apps, L2TP/IPsec is a confirmed mode in the Windows and macOS VPNclient apps. It can also be set up manually on compatible phones, routers and other clients that offer L2TP/IPsec. Support depends on the device's operating system, client and router capabilities; not every modern phone includes a built-in L2TP/IPsec client. Manual setup details are in the Help Center.
Download links for every platform are on the white label apps page. Setup help is in the Help Center.
L2TP/IPsec in a White Label VPN Offering
Most resellers never need to promote L2TP/IPsec. It is useful to know it exists for the occasional customer with an older system, but WireGuard, OpenVPN and IKEv2 should be presented first.
If a customer asks for manual L2TP/IPsec settings, point them to the Help Center rather than publishing configuration values on your own marketing pages.
L2TP/IPsec FAQ
Does L2TP encrypt VPN traffic?
No, not on its own. L2TP only creates the tunnel. In the L2TP/IPsec service VPNresellers provides, IPsec supplies the encryption and integrity protection.
Why does VPNresellers still offer L2TP/IPsec?
For compatibility with older devices and systems that do not support modern protocols. For new setups we recommend WireGuard or IKEv2.
Where can L2TP/IPsec be used?
L2TP/IPsec is a mode in the Windows and macOS VPNclient apps, and it can be set up manually on compatible phones, routers and other clients. Availability depends on the device and client; not every modern phone has built-in L2TP/IPsec support.
Where can I find manual L2TP/IPsec settings?
Manual configuration details are in the VPNresellers Help Center. We do not repeat connection secrets on marketing pages.
Background reading: RFC 3193 (Securing L2TP using IPsec)
Cover Legacy Devices, Lead With Modern Protocols
L2TP/IPsec is there when you need it, alongside WireGuard, OpenVPN and IKEv2 in the included apps.
Read the VPNresellers API documentation →