WireGuard is a small, fast VPN: each side has a key pair, and each peer is identified by its public key and the addresses it is allowed to use. The configuration is short, but the keys must be made on the machines that use them, never copied from a web page.
The server lists an address inside the tunnel and a UDP port, then one [Peer] per client with that client's public key and the tunnel address it may use. AllowedIPs on the server is what the peer may send from and what is routed to it.
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = <server private key>
[Peer]
PublicKey = <alice public key>
AllowedIPs = 10.8.0.2/32Private keys must never be generated by a website or shared in chat. The setup script runs wg genkey on the server, writes the keys with restrictive permissions and fills them into the files.
wg genkey | tee server.key | wg pubkey > server.pubOn the client, AllowedIPs decides what goes through the VPN. 0.0.0.0/0, ::/0 sends everything, IPv6 included, so nothing leaks around it. A list of networks sends only those.
A peer can be a whole network: list the networks behind it on the server's AllowedIPs for that peer, and make sure both sides route between the tunnel and their LAN.
To let clients reach the internet through the server, enable IP forwarding and masquerade the tunnel network on the outgoing interface. The PostUp and PostDown lines do this when the tunnel starts and stops.
Open the WireGuard VPN generator
It adds a symmetric key on top of the public-key exchange, which protects the recorded traffic if public-key cryptography is ever broken.
It sends a small packet every N seconds so a client behind NAT stays reachable. 25 is the usual value.
Check that the UDP port is open in the firewall, that the endpoint is correct on the clients, and that IP forwarding is on if clients should reach other networks.