WireGuard Server and Client Configuration

WireGuard is a small, fast VPN: each side has a key pair, and each peer is identified by its public key and the addresses it is allowed to use. The configuration is short, but the keys must be made on the machines that use them, never copied from a web page.

Server and peers

The server lists an address inside the tunnel and a UDP port, then one [Peer] per client with that client's public key and the tunnel address it may use. AllowedIPs on the server is what the peer may send from and what is routed to it.

[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = <server private key>

[Peer]
PublicKey = <alice public key>
AllowedIPs = 10.8.0.2/32

Keys come from your machine

Private keys must never be generated by a website or shared in chat. The setup script runs wg genkey on the server, writes the keys with restrictive permissions and fills them into the files.

wg genkey | tee server.key | wg pubkey > server.pub

Full tunnel or split tunnel

On the client, AllowedIPs decides what goes through the VPN. 0.0.0.0/0, ::/0 sends everything, IPv6 included, so nothing leaks around it. A list of networks sends only those.

Site to site

A peer can be a whole network: list the networks behind it on the server's AllowedIPs for that peer, and make sure both sides route between the tunnel and their LAN.

Forwarding and NAT

To let clients reach the internet through the server, enable IP forwarding and masquerade the tunnel network on the outgoing interface. The PostUp and PostDown lines do this when the tunnel starts and stops.

Open the WireGuard VPN generator

Frequently asked questions

Why is a preshared key worth adding?

It adds a symmetric key on top of the public-key exchange, which protects the recorded traffic if public-key cryptography is ever broken.

What does PersistentKeepalive do?

It sends a small packet every N seconds so a client behind NAT stays reachable. 25 is the usual value.

Why can I not reach the server after starting the tunnel?

Check that the UDP port is open in the firewall, that the endpoint is correct on the clients, and that IP forwarding is on if clients should reach other networks.

Guides