Back to updates
UpdatedAug 1, 2026

Docker IPsec VPN Server — Updated!

Docker-based IPsec VPN server supporting IPsec/L2TP, Cisco IPsec, and IKEv2 with automatic credential generation and multi-platform client configuration.

Share

English | 简体中文 | 繁體中文 | Русский

IPsec VPN Server on Docker

Build Status GitHub Stars Docker Stars Docker Pulls

Docker image to run an IPsec VPN server, with IPsec/L2TP, Cisco IPsec and IKEv2.

Based on Alpine 3.23 or Debian 12 with Libreswan (IPsec VPN software) and xl2tpd (L2TP daemon).

An IPsec VPN encrypts your network traffic, so that nobody between you and the VPN server can eavesdrop on your data as it travels via the Internet. This is especially useful when using unsecured networks, e.g. at coffee shops, airports or hotel rooms.

Features:

  • Automatically generates VPN credentials and IKEv2 configuration on first start
  • Supports IKEv2 with strong and fast ciphers (e.g. AES-GCM)
  • Generates VPN profiles to auto-configure iOS, macOS and Android devices
  • Supports Windows, macOS, iOS, Android, Chrome OS and Linux as VPN clients
  • Includes a helper script to manage IKEv2 users and certificates
  • Automatically built and published via GitHub Actions
  • Persistent data via a Docker volume
  • Multi-arch: linux/amd64, linux/arm64, linux/arm/v7

Also available:

📘 Interested in self-hosted AI? The Self-Hosted AI Builder’s Guide is a practical guide to building, securing, and operating your own private AI stack.

Quick start

Use this command to set up an IPsec VPN server on Docker:

docker run \
    --name ipsec-vpn-server \
    --restart=always \
    -v ikev2-vpn-data:/etc/ipsec.d \
    -v /lib/modules:/lib/modules:ro \
    -p 500:500/udp \
    -p 4500:4500/udp \
    -d --privileged \
    hwdsl2/ipsec-vpn-server

Your VPN login details will be randomly generated. See Retrieve VPN login details.

Alternatively, you may set up IPsec VPN without Docker. To learn more about how to use this image, read the sections below.

Community

Requirements

  • A Linux server with a public IP address or DNS name
  • Docker installed
  • VPN ports open in your firewall (UDP 500 and 4500)
  • You may also use Podman to run this image, after creating an alias for docker

Note: Advanced users can use this image on macOS with Docker for Mac. Before using IPsec/L2TP mode, you may need to restart the container once with docker restart ipsec-vpn-server. This image does not support Docker for Windows.

Download

Get the trusted build from the Docker Hub registry:

docker pull hwdsl2/ipsec-vpn-server

Alternatively, you may download from Quay.io:

docker pull quay.io/hwdsl2/ipsec-vpn-server
docker image tag quay.io/hwdsl2/ipsec-vpn-server hwdsl2/ipsec-vpn-server

Supported platforms: linux/amd64, linux/arm64 and linux/arm/v7.

Advanced users can build from source code on GitHub.

Image comparison

Two pre-built images are available. The default Alpine-based image is only ~19 MB.

Alpine-basedDebian-based
Image namehwdsl2/ipsec-vpn-serverhwdsl2/ipsec-vpn-server:debian
Compressed size~ 19 MB~ 62 MB
Base imageAlpine Linux 3.23Debian Linux 12
Platformsamd64, arm64, arm/v7amd64, arm64, arm/v7
Libreswan version5.45.4
IPsec/L2TP✅✅
Cisco IPsec✅✅
IKEv2✅✅

Note: To use the Debian-based image, replace every hwdsl2/ipsec-vpn-server with hwdsl2/ipsec-vpn-server:debian in this README. These images are not currently compatible with Synology NAS systems.

I want to use the older Libreswan version 4.

It is generally recommended to use the latest Libreswan version 5, which is the default version in this project. However, if you want to use the older Libreswan version 4, you can build the Docker image from source code:

git clone https://github.com/hwdsl2/docker-ipsec-vpn-server
cd docker-ipsec-vpn-server
# Specify Libreswan version 4
sed -i 's/SWAN_VER=5\..*/SWAN_VER=4.15/' Dockerfile Dockerfile.debian
# To build Alpine-based image
docker build -t hwdsl2/ipsec-vpn-server .
# To build Debian-based image
docker build -f Dockerfile.debian -t hwdsl2/ipsec-vpn-server:debian .

How to use this image

Environment variables

Note: All the variables to this image are optional, which means you don't have to type in any variable, and you can have an IPsec VPN server out of the box! To do that, create an empty env file using touch vpn.env, and skip to the next section.

This Docker image uses the following variables, that can be declared in an env file (see example):

VPN_IPSEC_PSK=your_ipsec_pre_shared_key
VPN_USER=your_vpn_username
VPN_PASSWORD=your_vpn_password

This will create a user account for VPN login, which can be used by your multiple devices*. The IPsec PSK (pre-shared key) is specified by the VPN_IPSEC_PSK environment variable. The VPN username is defined in VPN_USER, and VPN password is specified by VPN_PASSWORD.

Additional VPN users are supported, and can be optionally declared in your env file like this. Usernames and passwords must be separated by spaces, and usernames cannot contain duplicates. All VPN users will share the same IPsec PSK.

VPN_ADDL_USERS=additional_username_1 additional_username_2
VPN_ADDL_PASSWORDS=additional_password_1 additional_password_2

Categories