finds.dev← search

// the find

hwdsl2/setup-ipsec-vpn

★ 28,629 · Shell · NOASSERTION · updated Sep 2026

Set up your own IPsec VPN server in just a few minutes, with IPsec/L2TP, Cisco IPsec and IKEv2. Supports Ubuntu, Debian, CentOS/RHEL, Alpine Linux and Raspberry Pi OS. Includes client config and management scripts.

A shell script collection that automates standing up a full-featured IPsec VPN server (L2TP, Cisco IPsec/XAuth, IKEv2) on common Linux distros using Libreswan and xl2tpd. It's aimed at people who want a personal VPN on a cheap VPS without manually wrangling Libreswan config files.

The scripts have been battle-tested since 2014 across a huge range of distros and versions (Ubuntu, Debian, CentOS Stream, Alpine, RHEL, Raspberry Pi OS), which is rare longevity for a shell project. CI actually runs the install across multiple OS targets in GitHub Actions rather than just linting. The IKEv2 setup generates ready-to-import client profiles for iOS/macOS/Android/Windows, which is the fiddliest part of IKEv2 to get right by hand and the part most guides skip. Config changes are backed up with timestamped suffixes before being overwritten, so a bad run doesn't leave you with no way back.

It's a one-shot imperative installer, not something you can diff or re-apply idempotently — there's no Ansible/Terraform equivalent, so drift between servers over time is on you to track manually. Piping `wget ... | sudo sh` as the primary install path is a supply-chain risk by design; you're trusting DNS and TLS on get.vpnsetup.net every time you run it, and the repo doesn't offer a signed-release alternative. L2TP mode has a known multi-client-behind-NAT limitation that's only documented, not worked around, so users who don't read the README closely will hit broken connections from shared networks. Credential handling via env vars or in-script edits (`VPN_IPSEC_PSK`, etc.) means secrets often end up in shell history or world-readable scripts unless the user is careful, and the project doesn't nudge toward a safer pattern like a sourced env file with restricted permissions.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →