This guide shows you how to connect Linux to PremierVPN over IKEv2 using strongSwan. The easiest way is through NetworkManager on a desktop. There's also a command-line setup for headless machines.
Want a desktop app instead? PremierVPN has a native Linux app with WireGuard and a kill switch for Ubuntu and Debian and Fedora, RHEL, Rocky and AlmaLinux. The app signs in with your portal email and password.
Before you start: use your VPN credentials
Manual setups sign in with your VPN username and VPN password. These are separate from the email and password you use for the portal and the PremierVPN apps, and the portal login will not work here.
- Find both on your Dashboard under Your VPN credentials. Click Show to reveal the password.
- To change the VPN password, go to Settings › VPN Password. The new password applies from your next connection.
- Not sure which login is which? See Understanding your VPN credentials.
Option 1: NetworkManager (desktop)
Install the packages
Ubuntu / Debian:
sudo apt install network-manager-strongswan libcharon-extra-plugins
Fedora / RHEL / Rocky / AlmaLinux:
sudo dnf install NetworkManager-strongswan-gnome
Arch Linux:
sudo pacman -S strongswan networkmanager-strongswan
Log out and back in (or restart) so the network settings pick up the new VPN type.
Add the connection
- Open Settings › Network and click + next to VPN.
- Choose IPsec/IKEv2 (strongswan).
- Fill in:
- Name: any name, for example
PremierVPN UK - Server address: a hostname from the table below, for example
uk.premiervpn.net - Certificate: leave empty. Your system's trusted certificates are used.
- Authentication: EAP (Username/Password)
- Username: your VPN username
- Password: your VPN password
- Tick Request an inner IP address.
- Name: any name, for example
- Click Add, then switch the VPN on from the network menu.
Option 2: Command line (Ubuntu / Debian)
These steps use the classic ipsec.conf setup. On Fedora and RHEL the files live under /etc/strongswan/ and the command is strongswan instead of ipsec.
- Install strongSwan and the EAP plugins:
sudo apt install strongswan libcharon-extra-plugins libstrongswan-extra-plugins - Let strongSwan trust our servers' certificate authority (Let's Encrypt):
sudo ln -s /etc/ssl/certs/ISRG_Root_X1.pem /etc/ipsec.d/cacerts/ sudo ln -s /etc/ssl/certs/ISRG_Root_X2.pem /etc/ipsec.d/cacerts/ - Add this to
/etc/ipsec.conf, replacingYOUR_VPN_USERNAME:conn premiervpn keyexchange=ikev2 ike=aes256-sha256-modp2048 esp=aes256-sha256 dpdaction=restart dpddelay=30s dpdtimeout=120s left=%defaultroute leftsourceip=%config leftauth=eap-mschapv2 eap_identity=YOUR_VPN_USERNAME right=uk.premiervpn.net rightid=uk.premiervpn.net rightsubnet=0.0.0.0/0 rightauth=pubkey auto=add - Add your credentials to
/etc/ipsec.secrets:YOUR_VPN_USERNAME : EAP "YOUR_VPN_PASSWORD" - Protect the secrets file and connect:
sudo chmod 600 /etc/ipsec.secrets sudo ipsec restart sudo ipsec up premiervpn
To disconnect:
sudo ipsec down premiervpn
To connect automatically when strongSwan starts, change auto=add to auto=start.
Server hostnames
To change location, replace the hostname in both right= and rightid= (or in the NetworkManager server address). You can also copy any hostname from the Servers page in the portal.
| Location | Hostname |
|---|---|
| Denmark | dn.premiervpn.net |
| Finland | fn.premiervpn.net |
| France | fr.premiervpn.net |
| Germany | de.premiervpn.net |
| Israel | isr.premiervpn.net |
| Italy | it.premiervpn.net |
| Netherlands | nl.premiervpn.net |
| Norway | no.premiervpn.net |
| Poland | pl.premiervpn.net |
| Romania | ro.premiervpn.net |
| Spain | sp.premiervpn.net |
| Sweden | sw.premiervpn.net |
| Switzerland | swiss.premiervpn.net |
| Turkey | tr.premiervpn.net |
| United Kingdom (London) | uk.premiervpn.net |
| Argentina | ar.premiervpn.net |
| Brazil | br.premiervpn.net |
| Canada | ca.premiervpn.net |
| Mexico | mx.premiervpn.net |
| Peru | pe.premiervpn.net |
| United States (Kansas) | ks.premiervpn.net |
| United States (Los Angeles) | la.premiervpn.net |
| United States (New York) | ny.premiervpn.net |
| United States (Santa Clara) | sc.premiervpn.net |
| Australia | au.premiervpn.net |
| Hong Kong | hk.premiervpn.net |
| India | in.premiervpn.net |
| Japan | jp.premiervpn.net |
| Singapore | sg.premiervpn.net |
| South Korea | sk.premiervpn.net |
Troubleshooting
"Authentication failed" or "EAP method not supported"
- Use your VPN username and VPN password from the Dashboard, not your portal email and password.
- Make sure the EAP plugins are installed (
libcharon-extra-pluginson Ubuntu and Debian).
"no trusted RSA/ECDSA public key found" or a certificate error
strongSwan can't find the certificate authority. For the command-line setup, check the links you created in /etc/ipsec.d/cacerts/ point to real files and update the ca-certificates package. Then run sudo ipsec restart.
"no proposal chosen"
The server didn't accept the ike= or esp= settings. Remove those two lines so strongSwan offers its defaults, then try again.
It won't connect on some networks
IKEv2 uses UDP ports 500 and 4500, which some networks block. Try another network or use OpenConnect (port 443).
Still stuck? Open a support ticket and tell us your distribution, which setup you used and the output of sudo ipsec statusall.