##How to get OS X certificate-based IKEv2 working with strongSwan
Out of the box, El Capitan does not play nicely with strongSwan if you intend to use certificate-based login without EAP. OS X unfortunately does not provide a means of directly configuring the VPN parameters, so you have to leverage Apple's profile system to create a VPN configuration that will work with some strongSwan builds.
- Download 'Apple Configurator 2' from the App Store. Load it then create a New Profile.
- In 'General' give your profile a name.