Protocol reference

IKEv2 / IPsec

IKEv2 negotiates security associations; IPsec protects IP traffic.

Three checks when reading a VPN or proxy protocol: identity and keys, data transfer, and traffic and DNS policy.
Check authentication, data transfer, and traffic/DNS policy separately. VPNs and proxies can cover different traffic; routing and DNS depend on the protocol and client.
Transport
UDP 500 / 4500 · IPsec
Protocol reference
Tunnel protocol
Address scope
Current reference

How the connection works

IKEv2 handles authentication and key negotiation. IPsec uses the negotiated associations to protect packets. MOBIKE adds mobility capabilities when the implementation and configuration support it. Traffic selectors, routes and DNS must still agree.

Configuration checkpoints

  • Record the server identity and whether authentication uses certificates, EAP or another supported method. The configured identity must match what the client verifies.
  • Check the negotiated IKE and IPsec associations, traffic selectors and NAT traversal. A completed IKE exchange alone does not prove that every destination is selected.
  • Check MOBIKE support before relying on network changes. Test Wi-Fi-to-mobile switching with the actual operating system and server configuration.

Verify the traffic path

  • Check IPv4 and IPv6 routes separately. A route for one address family does not demonstrate coverage of the other.
  • Check the resolver used by the operating system and by applications that select their own DNS service. A public DNS lookup on this site does not test your device for DNS leaks.
  • Observe a controlled disconnect on your own device. Protocol support does not establish a client kill switch or application-specific routing policy.

Diagnose a connection problem

Separate endpoint reachability, authentication, route selection and DNS resolution. Record the client version and the exact error; change one setting at a time. A handshake with no working traffic often needs route or resolver investigation, while an authentication error needs credentials or certificate checks.

Scope and limitations

Check algorithms, authentication and NAT traversal in the deployed implementation. Built-in operating-system support is not evidence that every deployment has identical security or roaming behavior.

This page explains a mechanism and a verification approach. It contains no original speed, regional-access or leak measurements. Throughput depends on the implementation, device, path and server; a protocol name cannot identify a universal winner.