Ubuntu服务器连接IKEv2 VPN服务器的标准替代方案及免手动输入EAP密码方法咨询
Hey there! I totally get it—charon-cmd gets the job done, but that manual password prompt every time is such a hassle, and it’s not the most server-friendly approach. Let’s walk through some standard alternatives and how to fix that annoying password issue.
Standard Alternatives to charon-cmd
1. strongSwan with Persistent Config Files
This is the most "standard" server-side solution—it lets you set up auto-connecting, persistent VPN connections without any interactive prompts. Here’s how to do it:
First, ensure strongSwan is installed (you likely already have it since charon-cmd is part of the suite):
sudo apt install strongswan strongswan-pki
Create the IPsec config file (/etc/ipsec.conf)
Add this configuration block (adjust values to match your VPN details):
conn ikev2-eap-vpn keyexchange=ikev2 left=%defaultroute leftauth=eap leftsourceip=%config right=host.domain rightauth=pubkey rightid=@host.domain rightsubnet=0.0.0.0/0 eap_identity=my-identity auto=start # Automatically connects on system boot
Add your EAP password to the secrets file (/etc/ipsec.secrets)
Add this line (replace your-password-here with your actual password):
my-identity : EAP "your-password-here"
Lock down the secrets file to keep your password secure:
sudo chmod 600 /etc/ipsec.secrets
Restart the strongSwan service to apply changes:
sudo systemctl restart strongswan-starter sudo systemctl enable strongswan-starter # Enable auto-start on boot
2. NetworkManager CLI (Great for Desktop/Server Hybrid Setups)
If you prefer using NetworkManager (common on Ubuntu desktop, but fully functional on servers too), you can set up the VPN via command line and skip manual prompts:
First install the required strongSwan plugin for NetworkManager:
sudo apt install network-manager-strongswan
Add the VPN connection
Run this command to create a new IKEv2 EAP connection:
nmcli connection add type vpn vpn-type strongswan con-name "IKEv2 Work VPN" \ vpn.gateway host.domain vpn.ipsec-ikev2-enable yes \ vpn.ipsec-auth-algorithm sha256 vpn.ipsec-esp-algorithms aes256-sha256 \ vpn.eap-method peap vpn.eap-identity my-identity
Save your EAP password
Store the password so you don’t have to enter it manually:
nmcli connection modify "IKEv2 Work VPN" vpn.secrets "eap-password=your-password-here"
Start the connection (and enable auto-connect)
nmcli connection up "IKEv2 Work VPN" nmcli connection modify "IKEv2 Work VPN" connection.autoconnect yes # Auto-start on boot
Fixing the Manual Password Prompt for charon-cmd
If you still want to stick with charon-cmd, you can bypass the prompt by feeding the password via standard input. Here are two safe ways:
1. Pipe the password directly
Use echo to send the password to charon-cmd:
echo "your-password-here" | sudo charon-cmd --host host.domain --identity host.domain --profile ikev2-eap --eap-identity my-identity
2. Use a secure script
Create a small script (e.g., vpn-connect.sh) to handle the connection, and restrict access to keep your password safe:
#!/bin/bash echo "your-password-here" | sudo charon-cmd --host host.domain --identity host.domain --profile ikev2-eap --eap-identity my-identity
Make the script executable and lock down permissions:
chmod 700 vpn-connect.sh
Now just run ./vpn-connect.sh whenever you need to connect.
Hope these solutions make your VPN setup way smoother! Let me know if you need help tweaking any of the configs.
备注:内容来源于stack exchange,提问作者Ningaro

