

Both are configured automatically when using Apple AirPorts as gateway devices. L2TP is a bit more complicated, running over 1701, but also the IP-ESP protocol (IP Protocol 50). While deprecated(ish) PPTP runs over port 1723. Once configured, open incoming ports on the router/firewall.
IPSECURITAS HIGH SIERRA PASSWORD
Shared Secret: A passphrase that must be supplied by the client prior to getting a username and password prompt.Save Configuration Profile: Use this button to export configuration profiles to a file, which can then be distributed to client systems (macOS using the profiles command, iOS using Apple Configurator or both using Profile Manager).Routes: Select which interface (VPN or default interface of the client system) that a client connects to each IP address and subnet mask over.As well as the Search Domains configuration. DNS Settings: The name servers used once a VPN client has connected to the server.Client Addresses: The dynamic pool of addresses provided when clients connect to the VPN.Additionally, there are three fields, each with an Edit button that allows for configuration: In this example, we’ll configure a shared secret by providing a password in the Shared Secret field. L2TP requires a shared secret or an SSL certificate. The setting used becomes the address for the VPN service in the Everyone profile. The VPN Host Name field is used by administrators leveraging profiles. The VPN Settings screen has a number of options available, as seen here.

To setup the VPN service, open the Server app and click on VPN in the Server app sidebar. Setting Up The VPN Service In macOS Server And while PPTP is still accessible via the command line, L2TP is now configured by default when you setup the server using the Server app.

The server was once capable of running the two most commonly used VPN protocols: PPTP and L2TP. And as with many a service on macOS Server, this is one of the easiest VPN servers you’ll ever setup. MacOS Server has long had a VPN service to allow client computers to connect to a network even when they’re out of the home or office.
