۵۰٪ تخفیف روی همه پلان‌ها، محدود. شروع از $2.48/mo

L2TP/IPsec VPS Hosting

The VPN every phone
already speaks.

Native L2TP/IPsec on a cloud VPS. AMD EPYC + NVMe + 40 Gbps + dedicated IP.
Cloudzy has been the independent cloud for builders since 2008.
122,000+ developers, rated 4.6/5. From $2.48/mo.

4.6 · ۷۰۸ نظر در Trustpilot

Starting at $2.48/mo · 50% off · No credit card required

~ ssh root@vps-lon-001 tunnel up
root@vps-lon-001:~# apt install -y strongswan xl2tpd
Setting up strongswan-starter (5.9.x-1) ...
root@vps-lon-001:~# ipsec status
Routed Connections:
L2TP-PSK: %any...0.0.0.0/0 PASS
Security Associations (1 up):
L2TP-PSK[1]: ESTABLISHED
root@vps-lon-001:~# ss -ulnp | grep -E '500|4500'
UNCONN 0.0.0.0:500 charon
UNCONN 0.0.0.0:4500 charon
root@vps-lon-001:~# _

L2TP/IPsec VPS at a glance

Cloudzy hosts L2TP/IPsec-ready VPS instances from 12 regions across North America, Europe, the Middle East, and Asia, starting at $2.48 per month. Plans run on AMD EPYC با فضای ذخیره‌سازی NVMe, 40 Gbps uplinks and a dedicated IPv4. Each VPS provisions in 60 seconds and ships strongSwan or Libreswan for IPsec plus xl2tpd for L2TP, connectable from any iOS, macOS, Windows, or Android device using the built-in VPN client. Cloudzy has operated independently since 2008 and is rated 4.6 / 5 by 708+ reviewers در Trustpilot.

Starting price
$2.48 / month
Provisioning
60 seconds
IKE port
UDP 500
NAT-T port
UDP 4500
بازگشت وجه
14 days
تأسیس
2008

Why builders pick Cloudzy

The VPN every device already trusts.

The four things buyers actually compare us on.

Native OS support

iOS, macOS, Windows, Android, all four ship L2TP/IPsec in System Settings. No app to install, no sideload, no fuss.

۱۴ روز ضمانت بازگشت وجه

Try it. If your tunnel doesn't behave, refund within 14 days, no questions. Cancel anytime from the dashboard.

99.95% uptime SLA

Your VPN needs to be there when you reach for it. 12 monitored regions, public SLA at status.cloudzy.com.

Real humans on chat

Live chat replies typically under 5 minutes. Engineers, not script-readers. Median resolution under 1 hour.

Pick your stack

One tunnel,
every OS connects.

strongSwan or Libreswan for IPsec, xl2tpd for the L2TP layer. iOS, macOS, Windows, and Android ship native clients, no app to install. Pre-shared key + username/password and you're in.

Custom ISO upload supported on every plan
Ubuntu
22.04 / 24.04 LTS · strongSwan
Debian
12 / 13 · strongSwan + xl2tpd
AlmaLinux
9 · Libreswan
Rocky Linux
9 · Libreswan
strongSwan
Modern IPsec daemon
Libreswan
RHEL-family IPsec
xl2tpd
L2TP layer · pairs with IPsec
Custom ISO
Bring your own image

Use cases

What people run on an
L2TP/IPsec VPS.

Onboard non-technical users

Family, parents, a small team, they don't need to install an app. Three fields in iOS Settings, done. Lowest possible support load.

Locked-down work devices

Some corporate phones won't let you sideload third-party VPN clients. The OS-level L2TP/IPsec setting works without admin rights.

Site-to-site between offices

Most consumer and SMB routers (MikroTik, ASUS, Ubiquiti, Cisco) speak IPsec natively. Bridge two offices without buying extra hardware.

Pi-hole + native VPN

Run Pi-hole on the same VPS, push it as the DNS via L2TP/IPsec, and every device on the tunnel gets ad-blocking, including grandma's iPad.

Always-on access to home

Reach your NAS, Plex, Home Assistant from the phone's built-in VPN. No port-forwarding, no DDNS, no third-party app to keep updated.

Geo-bypass for legitimate content

Watch the streaming library you legally subscribe to from another country, or work-from-anywhere on a corporate firewall that whitelists your VPS IP.

60s
Provisioning
40 Gbps
Uplink
NVMe-only
Storage
12
منطقه‌ها
99.95%
آپتایم SLA
14 days
بازگشت وجه

شبکه جهانی

12 regions. Four continents.
Pick your exit point.

Drop your IPsec tunnel where it makes sense. Median P50 latency under 10 ms in North America and Europe.

us-utah-1us-dal-1us-lax-1us-nyc-1us-mia-1eu-ams-1eu-lon-1eu-fra-1eu-zrh-1me-dxb-1ap-sgp-1ap-tyo-1

قیمت‌گذاری

فقط برای آنچه مصرف می‌کنید بپردازید. That's it.

Hourly, monthly, or yearly. No egress fees. Currently ۵۰٪ تخفیف all plans.

512 MB DDR5

Personal · 1-2 devices

$2.48 /ماه
$4.95/mo ۵۰%-
Deploy now
۱۴ روز ضمانت بازگشت وجه
  • 1 vCPU @ EPYC
  • 20 GB NVMe
  • 1 TB · 40 Gbps
  • Dedicated IPv4 + IPv6
  • Root SSH · KVM
1 GB DDR5

Family / small team · 5 peers

$3.48 /ماه
$6.95/mo ۵۰%-
Deploy now
۱۴ روز ضمانت بازگشت وجه
  • 1 vCPU @ EPYC
  • 25 GB NVMe
  • 1 TB · 40 Gbps
  • Dedicated IPv4 + IPv6
  • Root SSH · KVM
2 GB DDR5

Office tunnel · 25+ peers

$7.475 /ماه
$14.95/mo ۵۰%-
Deploy now
۱۴ روز ضمانت بازگشت وجه
  • 1 vCPU @ EPYC
  • 60 GB NVMe
  • 3 TB · 40 Gbps
  • Dedicated IPv4 + IPv6
  • Root SSH · KVM

FAQ. L2TP/IPsec VPS

Common questions, straight answers.

What is an L2TP/IPsec VPS?

An L2TP/IPsec VPS is a cloud server running the Layer 2 Tunneling Protocol over IPsec, the VPN protocol that's built into iOS, macOS, Windows, Android, and most consumer routers, so the user doesn't need to install any third-party client. Cloudzy gives you root access in 60 seconds; install strongSwan or Libreswan, configure a pre-shared key plus username, and any phone or laptop can connect from the OS-level VPN settings.

Why L2TP/IPsec instead of WireGuard or OpenVPN?

Because every device already supports it. iOS, macOS, Windows, and Android all ship a native L2TP/IPsec client in System Settings, there's no app to install or sideload. That makes it the easy pick when you need to onboard non-technical users, support locked-down enterprise devices, or work on a phone you don't fully control.

Which packages do I install on the VPS?

Most setups use strongSwan (modern IPsec implementation, actively maintained) or Libreswan (the IPsec daemon Red Hat ships in RHEL/Alma/Rocky). Both are in every major distro's package manager. Pair with xl2tpd for the L2TP layer. There are also turnkey scripts (e.g. setup-ipsec-vpn.sh) that wire it all up in one command.

Which ports does L2TP/IPsec need open?

UDP 500 (IKE), UDP 4500 (NAT-T), and IP protocol 50 (ESP). Some restrictive networks block ESP, in which case NAT-T over UDP 4500 is the fallback. If both are blocked you'll need OpenVPN over TCP 443, which is one reason many users run multiple VPN protocols on the same VPS.

How do I connect from my iPhone or Mac?

On iPhone: Settings → VPN & Device Management → Add VPN Configuration → L2TP. Enter the server IP, your account username, the password, and the pre-shared key. Toggle the VPN switch on. On Mac it's System Settings → Network → VPN. No third-party app required at any point.

Is the VPN traffic logged?

We don't log VPN traffic itself, what flows through your tunnel is your business. Standard infrastructure logs (login attempts to the VPS, billing) exist as you'd expect from any cloud provider. The IPsec daemon's own log keeps connection events; you can disable or rotate them yourself.

Does L2TP/IPsec work behind NAT or carrier-grade NAT?

Yes. NAT Traversal (NAT-T) over UDP 4500 handles the common cases. Some mobile carriers and corporate networks block IPsec entirely; in that case you'd want OpenVPN over TCP 443 or WireGuard on a different port. You can run all three on the same VPS.

How fast is L2TP/IPsec on a Cloudzy VPS?

L2TP/IPsec has more overhead than WireGuard. IPsec is encryption + L2TP is encapsulation, so you pay twice. On a 4 GB / 2 vCPU AMD EPYC plan you'll comfortably see hundreds of Mbps. For raw throughput pick WireGuard; for native-OS-client convenience pick L2TP/IPsec.

Can I run other services on the same VPS?

Yes. L2TP/IPsec is just a daemon listening on a few ports, you can also run a web server, Pi-hole DNS, or any other workload alongside. Many users layer Pi-hole + IPsec to get private, ad-blocking VPN on a single $2.48/mo box.

Is there a money-back guarantee?

Yes, 14 days from purchase, no questions asked, full refund. Apply from the panel or email [email protected].

آماده‌ایم وقتی شما آماده‌اید.
Native VPN in 60 seconds.

Pick a region, click deploy, point your phone's built-in VPN client at it.

بدون نیاز به کارت اعتباری · ضمانت بازگشت وجه ۱۴ روزه · لغو در هر زمان