Skip to content

WireGuard VPN Quickstart

This quickstart connects one remote client to a Linux server with WireGuard. It routes traffic only to the server’s tunnel address; it does not route the client’s traffic to the server’s LAN or through the server as an internet exit node. Choose a private tunnel subnet that does not overlap with either endpoint’s existing networks.

The examples use 10.77.0.0/24, server address 10.77.0.1, client address 10.77.0.2, and UDP port 51820. Replace them if they conflict with your network plan.


Step 1: Install WireGuard and Create the Server Keys

01

Install WireGuard Tools and Generate Server Keys

Server Setup

Install the distribution’s WireGuard package, then create a private key directory and generate the server key pair as root. Run the key-generation commands once for a new server; keep the private key and never send it to a client.

Terminal window
sudo apt update
sudo apt install -y wireguard
Terminal window
sudo install -d -m 0700 /etc/wireguard
sudo sh -c 'umask 077; wg genkey > /etc/wireguard/server.key; wg pubkey < /etc/wireguard/server.key > /etc/wireguard/server.pub'
sudo cat /etc/wireguard/server.pub
❯ View Expected Console Output
u3k...server-public-key...X0=

The public key can be shared with the client. /etc/wireguard/server.key stays readable only by root.


Step 2: Generate a Client Key Pair

02

Keep the Client Private Key on the Client Device

Client Setup

Generate the client key pair on the device that will connect. Send only the public key to the server administrator. The Windows and mobile WireGuard apps can generate a key pair when you add a tunnel; use the Linux commands below for a Linux client.

Terminal window
mkdir -p "$HOME/wireguard-client"
cd "$HOME/wireguard-client"
umask 077
wg genkey > client.key
wg pubkey < client.key > client.pub
cat client.pub
❯ View Expected Console Output
Y7s...client-public-key...rE=

Keep the Linux client.key file private. The umask 077 command gives the generated files owner-only permissions.


Step 3: Create the Server and Client Configurations

03

Add the Peer Keys and Tunnel Addresses

Configuration

On the server, set CLIENT_PUBLIC_KEY to the public key received from the client. This command reads the server private key directly into the root-owned config without printing it. On a Linux client, create the file using its private key, the server public key, and the server’s public IP address or DNS name. In the Windows or mobile app, keep the generated private key in the app and add the same address and peer settings to that tunnel.

Terminal window
CLIENT_PUBLIC_KEY="paste-client-public-key-here"
sudo env CLIENT_PUBLIC_KEY="$CLIENT_PUBLIC_KEY" sh -c '
server_key=$(cat /etc/wireguard/server.key)
umask 077
cat > /etc/wireguard/wg0.conf <<EOF
[Interface]
Address = 10.77.0.1/24
ListenPort = 51820
PrivateKey = $server_key
[Peer]
PublicKey = $CLIENT_PUBLIC_KEY
AllowedIPs = 10.77.0.2/32
EOF
'
sudo chmod 0600 /etc/wireguard/wg0.conf

On a Linux client, install the WireGuard tools using the same package instructions as Step 1, then create client.conf in the directory from Step 2. Replace the example values first. In the Windows/mobile app, set the interface address to 10.77.0.2/32, and set the peer to the server public key, your server endpoint on UDP 51820, allowed IP 10.77.0.1/32, and persistent keepalive 25 seconds:

Terminal window
SERVER_PUBLIC_KEY="paste-server-public-key-here"
SERVER_ENDPOINT="vpn.example.net"
CLIENT_PRIVATE_KEY="$(cat client.key)"
cat > client.conf <<EOF
[Interface]
Address = 10.77.0.2/32
PrivateKey = $CLIENT_PRIVATE_KEY
[Peer]
PublicKey = $SERVER_PUBLIC_KEY
Endpoint = $SERVER_ENDPOINT:51820
AllowedIPs = 10.77.0.1/32
PersistentKeepalive = 25
EOF
unset CLIENT_PRIVATE_KEY
chmod 0600 client.conf
❯ View Expected Console Output

The server peer allows only 10.77.0.2/32, and the client routes only 10.77.0.1/32 through the tunnel. Keep the private keys out of shared notes, tickets, and source control.


Step 4: Allow the UDP Port and Start the Server

04

Permit UDP 51820 and Enable the WireGuard Interface

Firewall and Service

If the server is behind a router, reserve its LAN address and forward UDP port 51820 to it. Allow the same port in the server firewall, then start the wg-quick@wg0 service. The UFW or firewalld rule opens only WireGuard’s listener; it does not expose the tunnel subnet as a routed LAN.

Terminal window
sudo ufw allow 51820/udp
sudo ufw status
Terminal window
sudo systemctl enable --now wg-quick@wg0
sudo systemctl status wg-quick@wg0 --no-pager
sudo wg show wg0
❯ View Expected Console Output
interface: wg0
public key: u3k...X0=
listening port: 51820

Forwarding is not needed for this server-only tunnel. Add separate routing and firewall rules only if you intentionally want clients to reach the server’s LAN.


Step 5: Connect the Client and Check the Handshake

05

Bring Up the Client and Verify the Tunnel

Connection Test

Import the completed configuration into the Windows/mobile app and activate the tunnel. On a Linux client, install the config under /etc/wireguard and start it with wg-quick. A recent handshake confirms the peers exchanged authenticated packets; test a service on 10.77.0.1 to verify the traffic your deployment needs.

Terminal window
# Linux client only; run from the directory containing client.conf.
sudo install -m 0600 client.conf /etc/wireguard/wg-client.conf
sudo systemctl enable --now wg-quick@wg-client
sudo wg show wg-client
❯ View Expected Console Output
peer: u3k...server-public-key...X0=
endpoint: 203.0.113.20:51820
allowed ips: 10.77.0.1/32
latest handshake: 8 seconds ago
transfer: 1.24 KiB received, 1.08 KiB sent

References

Comments