FreeVPNNet

How to set up L2TP/IPsec on macOS

L2TP/IPsec is built into iPhone, iPad, Mac and Windows, so no app is needed. You need the server address, your username and password, and the pre-shared key.

Last reviewed

What you need

  • An active L2TP/IPsec configuration from this site
  • Server address, username, password and pre-shared key (IPsec) from your configuration page

App

Built into macOS

Where each detail goes

Account details and the matching fields in the app
On your configuration pageIn the app or settings
ServerServer / Server address / Gateway
UsernameAccount / User name
PasswordPassword
Pre-shared key (IPsec)Secret / Shared secret / Pre-shared key

Steps

  1. Open System Settings → VPN → Add VPN Configuration → L2TP over IPSec.

    Illustration of step 1: Open System Settings → VPN → Add VPN Configuration → L2TP over IPSec.
    Illustration — your app may look slightly different.
  2. Display name: any name. Server address: your Server. Account name: your username.

    Illustration of step 2: Display name: any name. Server address: your Server. Account name: your username.
    Illustration — your app may look slightly different.
  3. User authentication: Password — enter your password. Machine authentication: Shared secret — enter your Pre-shared key.

    Illustration of step 3: User authentication: Password — enter your password. Machine authentication: Shared secret — enter your Pre-shared key.
    Illustration — your app may look slightly different.
  4. Click Create, then switch the VPN on.

    Illustration of step 4: Click Create, then switch the VPN on.
    Illustration — your app may look slightly different.

Check that it works

The VPN status shows "Connected". Search the web for "what is my IP"; the location should match your server country.

Disconnect

Switch the VPN off in System Settings or from the menu bar.

Troubleshooting

Authentication failed

Re-type the username, password and pre-shared key exactly as shown (they are case-sensitive). The configuration may also have expired.

Connects on mobile data but not on Wi-Fi

Some routers block the ports L2TP/IPsec uses (UDP 500 and 4500). Try another network or use WireGuard or OpenVPN.

The L2TP option is missing

Android 12 and newer, and some managed devices, no longer offer L2TP/IPsec. Use WireGuard or OpenVPN instead.