How to set up IKEv2 manual connection on macOS

This guide will show you how to set up a manual IKEv2 connection on your macOS device. IKEv2 can help you connect to Surfshark servers in restricted network countries or on older macOS versions.

To proceed, you will need a computer running macOS and an active Surfshark subscription. If you don't have one yet, you can find the available plans on Surfshark's pricing page.

 

Get your credentials

NOTE: These are different from the email and password you use to log into your account dashboard or the app.

  1. Log in to your account on Surfshark website.

    NOTE: If you have any trouble accessing the page, you can also use this link or this link.
  2. Click on VPN and select Manual Setup:


     
  3. Click Desktop or mobile:


     
  4. Click IKEv2 to generate your credentials:


     
  5. Once there, you can copy the username and the password by clicking the icon. You will need to paste these credentials later in the guide.

    For now, keep this browser tab open, as we will return to it shortly.
     

     

Download configuration files

NOTE: For the following steps, we recommend opening a new tab in your browser.

  1. Log in to your account on Surfshark website.

    NOTE: If you have any trouble accessing the page, you can also use this link or this link.
  2. Click on VPN and select Manual Setup:


     
  3. Click Desktop or mobile:


     
  4. Click IKEv2:


     
  5. Click Locations:


     
  6. From the location list, find the server you wish to connect to and click the Download button beside it:


     
  7. For now, keep this browser tab open, as we will return to it shortly:

 

Install the certificate

NOTE: For the following steps, we recommend opening a new tab in your browser.

  1. Log in to your account on Surfshark website.

    NOTE: If you have any trouble accessing the page, you can also use this link or this link.
  2. Click on VPN and select Manual Setup:


     
  3. Click Desktop or mobile:


     
  4. Click IKEv2:


     
  5. Click Locations:


     
  6. Scroll down to Other configuration files and locate the IKEv2 certificate. Click the download button to download the certificate file:


     
  7. Once the certificate is downloaded, open it directly or locate it in your Downloads folder and double-click the file:


     
  8. A Keychain Access prompt will appear asking for permission to add the Surfshark IKEv2 certificate to your login keychain. If prompted, enter your Mac credentials and click Add:


     
  9. Now open the Keychain Access application:

  10. Locate the Surfshark Root CA certificate in the list, then right-click it and select Get Info.

    NOTE: If you’re unable to locate the certificate in Keychain Access, drag the certificate file directly from your Downloads folder into the Keychain Access window.


     
  11. Expand the Trust section by clicking the triangle. Next to When using this certificate, select Always Trust:


     
  12. If prompted, enter your Mac password to confirm the change, then close Keychain Access.

 

Connect to the VPN

  1. Click the Apple menu  and select System Settings:


     
  2. Click Network in the left‑hand sidebar:

  3. Click VPN & Filters:


     
  4. Click the arrow icon and select IKEv2:


     
  5. You may be prompted to enter your device (administrator) credentials.
  6. A configuration window will appear. Fill the fields in as follows, then click Create:

    1.  
      • Display Name: Enter any name you’d like for the VPN connection.
      • Server Address: Enter the domain address you copied earlier (see the Select your location section of this guide).
      • Remote ID: Enter the same domain address as above.
      • Local ID: Leave this field empty.
      • User Authentication: Select Username and enter the VPN username and password you copied earlier (see the Get credentials section of this guide).

        NOTE: These are not your computer’s username and password.
         
  7. Locate the newly created VPN configuration and click the toggle next to it to connect:


     
  8. Once connected, the VPN status will change to Connected:


     
  9. To disconnect, click the toggle again:

 

Ensure the connection is successful

We always recommend checking if Surfshark VPN is working after setting it up for the first time. You can easily do it by performing Surfshark IP leak test and a DNS leak test. For your convenience, both are available on our website.

Was this article helpful?
Thank you for your feedback!