< Back

How to set up IKEv2 IPsec on Windows

This guide was created using Windows 10 operating system.

First of all, you will need to download Surfshark IKEv2 certificate here at the bottom of the page. 


After downloading the certificate, open it and a prompt window will appear.


Then, select to install in the Local machine (this option requires you to have administrative privileges) and then select the Trusted Root Certification Authorities store to install it.


Press Next and then Finish to complete the installation.

Setting up the VPN connection:

1. Open Windows start menu, type in 'Control panel' and open Control panel application.


2. Click on the Network and Internet category.


3. Then select Network and Sharing Center tab.


4. Click on the Set up a new connection or network option.


5. Select the Connect to a workplace option and press Next.


6. Choose Use my Internet connection (VPN) method.


7. Enter the following information:

Internet address: Enter the domain name of the server you wish to connect to.

You can find the whole list of Surfshark servers and their hostnames here under the Files tab.

Destination name: you can name this connection however you want.

Use a smart card: unmarked.

Remember my credentials: you can leave it unmarked if you wish to enter your credentials every time you connect.

Allow other people to use this connection: if you leave it unmarked, only the user that you are setting up this connection will be able to connect. (If you wish that all of the users would be able to connect, you require Administrator rights.)

After filling in all the fields, click Create.


8. Press Create and right-click the adapter that you have created. Select Properties and open the Security tab.

Set the following options:
Type of VPN: IKEv2;
Data encryption: Require encryption (disconnect if server declines);
Authentication: Use Extensible Authentication Protocol (EAP) and EAP-MSCHAPv2.

Then, click OK to save these changes.


9. Open your Network settings (you can do so in the bottom right corner of the screen by pressing the Network icon) and select Network & Internet settings.


10. In the newly opened window, select VPN, click on the newly created connection and select Advanced options.


11. In the Advanced option settings, click Edit and fill in your service credentials which you can find here under the Credentials tab. After that, click Save to confirm the changes.



12. Now, open your Network settings again, press on the newly created connection and click Connect.



13. To make sure that you have connected successfully, please take a look at this article.

If something's not going according to the tutorial or you have further questions, feel free to contact our Customer Success Sharks anytime - they will help you out!

Was this article helpful?