☁️ Cloud XpertSystemsSecure Communication & Networking Products
ZBEVPN Release 5 guide

IKEv2/IPsec in ZBEVPN: What It Is and How to Use It

ZBEVPN Release 5 — Build 4.6.6 adds IKEv2/IPsec as another selectable VPN protocol for Windows and Android, alongside the existing ZBEVPN connection choices.

Secure third-party payment processing

Cloud XpertSystems does not process, store, or have access to full credit card numbers, CVV codes, or bank authentication details.

When you purchase ZBEVPN through Google Play, Samsung Galaxy Store, or Aptoide, payment processing is handled by that marketplace's billing system.

When you purchase ZBEVPN directly from our website, payment processing is handled by Stripe, an independent third-party payment processor that is not owned or operated by Cloud XpertSystems.

One ZBEVPN account. Multiple VPN technologies.

IKEv2/IPsec is an additional protocol choice, not a replacement for WireGuard or Zclipse. Select the protocol that works best for your device and network while keeping the same ZBEVPN account, subscription and location-selection experience.

What is IKEv2/IPsec?

IKEv2 means Internet Key Exchange version 2. It establishes and authenticates the secure relationship between your device and a VPN endpoint. IPsec protects the network traffic carried through the resulting tunnel.

IKEv2 is a standards-based VPN technology rather than a proprietary ZBEVPN-only protocol. In ZBEVPN Release 5 it is available as another protocol option for supported Windows and Android connections.

How ZBEVPN authenticates an IKEv2 connection

1. The VPN endpoint proves its identity

Before user authentication proceeds, the IKEv2 client validates the VPN endpoint's digital certificate. This gives the client a way to confirm the expected server identity before trusting the subsequent EAP authentication exchange.

2. The session uses challenge-response authentication

ZBEVPN uses EAP-MSCHAPv2 for the session-authentication stage. The exchange uses challenge-response values rather than simply sending a reusable password as plaintext across the network.

3. ZBEVPN supplies temporary session credentials

You do not manually configure a permanent IKEv2 username and password. ZBEVPN provisions temporary credentials for the selected endpoint as part of the connection workflow and manages those credentials as part of the session lifecycle.

Native Windows IKEv2 integration

On Windows, ZBEVPN uses the operating system's native Windows RAS/IKEv2 VPN stack. Windows performs the underlying IKEv2/IPsec negotiation and tunnel management instead of ZBEVPN installing a separate third-party IKE engine.

This keeps IKEv2 integrated with the Windows networking and security components already designed to support native VPN connections.

Native Android IKEv2 integration

On supported Android versions, ZBEVPN uses Android's platform-managed IKEv2/IPsec facilities through the platform VPN profile architecture. The operating system manages the IKEv2/IPsec tunnel rather than requiring ZBEVPN to implement a separate packet-forwarding engine for this protocol.

The Android client also displays IKE tunnel-address information and session traffic counters so users can see tunnel details and traffic activity while connected.

Full-tunnel Internet protection and location selection

IKEv2 uses the normal ZBEVPN location-selection workflow. Select a VPN location, choose IKEv2 as the protocol and connect. ZBEVPN handles endpoint selection, readiness synchronization, temporary credential provisioning, authentication and native VPN setup.

When the IKEv2 tunnel is connected, Internet traffic is routed through the selected ZBEVPN endpoint so websites and online services see the VPN endpoint's public Internet address rather than the device's normal public address.

When should I try IKEv2?

IKEv2 is useful when you want a standards-based IPsec VPN, prefer operating-system-native VPN integration, or want another protocol option to compare on a particular device or network.

Different networks behave differently. A protocol that performs well on one broadband, Wi-Fi or mobile path may behave differently elsewhere. ZBEVPN's multi-protocol design lets you choose rather than forcing every connection through one tunnel technology.

How do I use IKEv2 in ZBEVPN?

  1. Open ZBEVPN.
  2. Sign in normally.
  3. Select your VPN location.
  4. Open Protocol.
  5. Select IKEv2.
  6. Press Connect.

No manual native-VPN profile editing is required for the normal ZBEVPN workflow.

Do I need a separate IKEv2 username or password?

No. Use your normal ZBEVPN account. The application obtains temporary connection credentials automatically after validating your authenticated ZBEVPN session and selected endpoint. Those credentials are part of the VPN connection process and are not another permanent customer password to manage.

Is IKEv2 replacing WireGuard or Zclipse?

No. IKEv2 is an additional protocol choice. Release 5 expands the ZBEVPN protocol portfolio while preserving the existing WireGuard and Zclipse connection methods.

One ZBEVPN account. Multiple VPN technologies. Choose the protocol that works best for your device and network.

ZBEVPN Release 5 — Build 4.6.6

Release 5 adds IKEv2/IPsec protocol selection, certificate verification of the selected IKEv2 endpoint, EAP-MSCHAPv2 challenge-response session authentication, automatic temporary credential provisioning, endpoint-readiness synchronization, native Windows and Android IKEv2 integration, Android tunnel-IP display and Android IKEv2 session traffic counters.

Core functional testing has exercised endpoint selection, credential issuance, tunnel establishment, Internet routing, disconnect/reconnect and protocol switching across multiple VPN locations. Broader device, network, lifecycle and regression testing remains part of normal ongoing release validation.

Download ZBEVPN Release 5 for Windows or Android →

Related guides

WireGuard vs OpenVPN on Windows: Practical Differences
What Makes a Good VPN?
Why Does My VPN Keep Disconnecting?
Is Your VPN Really Working?