WireGuard VPN Quickstart
This quickstart connects one remote client to a Linux server with WireGuard. It routes traffic only to the server’s tunnel address; it does not route the client’s traffic to the server’s LAN or through the server as an internet exit node. Choose a private tunnel subnet that does not overlap with either endpoint’s existing networks.
The examples use 10.77.0.0/24, server address 10.77.0.1, client address 10.77.0.2, and UDP port 51820. Replace them if they conflict with your network plan.
Step 1: Install WireGuard and Create the Server Keys
Install WireGuard Tools and Generate Server Keys
Server SetupInstall the distribution’s WireGuard package, then create a private key directory and generate the server key pair as root. Run the key-generation commands once for a new server; keep the private key and never send it to a client.
sudo apt updatesudo apt install -y wireguardsudo dnf install -y wireguard-toolssudo install -d -m 0700 /etc/wireguardsudo sh -c 'umask 077; wg genkey > /etc/wireguard/server.key; wg pubkey < /etc/wireguard/server.key > /etc/wireguard/server.pub'sudo cat /etc/wireguard/server.pub❯ View Expected Console Output
u3k...server-public-key...X0=The public key can be shared with the client. /etc/wireguard/server.key stays readable only by root.
Step 2: Generate a Client Key Pair
Keep the Client Private Key on the Client Device
Client SetupGenerate the client key pair on the device that will connect. Send only the public key to the server administrator. The Windows and mobile WireGuard apps can generate a key pair when you add a tunnel; use the Linux commands below for a Linux client.
mkdir -p "$HOME/wireguard-client"cd "$HOME/wireguard-client"umask 077wg genkey > client.keywg pubkey < client.key > client.pubcat client.pub1. Create a new, empty tunnel in the WireGuard app.2. Let the app generate its private and public key pair.3. Copy or export only the public key for the server configuration.4. Keep the private key inside the app; do not send it to the server.❯ View Expected Console Output
Y7s...client-public-key...rE=Keep the Linux client.key file private. The umask 077 command gives the generated files owner-only permissions.
Step 3: Create the Server and Client Configurations
Add the Peer Keys and Tunnel Addresses
ConfigurationOn the server, set CLIENT_PUBLIC_KEY to the public key received from the client. This command reads the server private key directly into the root-owned config without printing it. On a Linux client, create the file using its private key, the server public key, and the server’s public IP address or DNS name. In the Windows or mobile app, keep the generated private key in the app and add the same address and peer settings to that tunnel.
CLIENT_PUBLIC_KEY="paste-client-public-key-here"sudo env CLIENT_PUBLIC_KEY="$CLIENT_PUBLIC_KEY" sh -c ' server_key=$(cat /etc/wireguard/server.key) umask 077 cat > /etc/wireguard/wg0.conf <<EOF[Interface]Address = 10.77.0.1/24ListenPort = 51820PrivateKey = $server_key
[Peer]PublicKey = $CLIENT_PUBLIC_KEYAllowedIPs = 10.77.0.2/32EOF'sudo chmod 0600 /etc/wireguard/wg0.confOn a Linux client, install the WireGuard tools using the same package instructions as Step 1, then create client.conf in the directory from Step 2. Replace the example values first. In the Windows/mobile app, set the interface address to 10.77.0.2/32, and set the peer to the server public key, your server endpoint on UDP 51820, allowed IP 10.77.0.1/32, and persistent keepalive 25 seconds:
SERVER_PUBLIC_KEY="paste-server-public-key-here"SERVER_ENDPOINT="vpn.example.net"CLIENT_PRIVATE_KEY="$(cat client.key)"cat > client.conf <<EOF[Interface]Address = 10.77.0.2/32PrivateKey = $CLIENT_PRIVATE_KEY
[Peer]PublicKey = $SERVER_PUBLIC_KEYEndpoint = $SERVER_ENDPOINT:51820AllowedIPs = 10.77.0.1/32PersistentKeepalive = 25EOFunset CLIENT_PRIVATE_KEYchmod 0600 client.conf❯ View Expected Console Output
The server peer allows only 10.77.0.2/32, and the client routes only 10.77.0.1/32 through the tunnel. Keep the private keys out of shared notes, tickets, and source control.
Step 4: Allow the UDP Port and Start the Server
Permit UDP 51820 and Enable the WireGuard Interface
Firewall and ServiceIf the server is behind a router, reserve its LAN address and forward UDP port 51820 to it. Allow the same port in the server firewall, then start the wg-quick@wg0 service. The UFW or firewalld rule opens only WireGuard’s listener; it does not expose the tunnel subnet as a routed LAN.
sudo ufw allow 51820/udpsudo ufw statussudo firewall-cmd --permanent --add-port=51820/udpsudo firewall-cmd --reloadsudo firewall-cmd --list-portssudo systemctl enable --now wg-quick@wg0sudo systemctl status wg-quick@wg0 --no-pagersudo wg show wg0❯ View Expected Console Output
interface: wg0 public key: u3k...X0= listening port: 51820Forwarding is not needed for this server-only tunnel. Add separate routing and firewall rules only if you intentionally want clients to reach the server’s LAN.
Step 5: Connect the Client and Check the Handshake
Bring Up the Client and Verify the Tunnel
Connection TestImport the completed configuration into the Windows/mobile app and activate the tunnel. On a Linux client, install the config under /etc/wireguard and start it with wg-quick. A recent handshake confirms the peers exchanged authenticated packets; test a service on 10.77.0.1 to verify the traffic your deployment needs.
# Linux client only; run from the directory containing client.conf.sudo install -m 0600 client.conf /etc/wireguard/wg-client.confsudo systemctl enable --now wg-quick@wg-clientsudo wg show wg-client❯ View Expected Console Output
peer: u3k...server-public-key...X0= endpoint: 203.0.113.20:51820 allowed ips: 10.77.0.1/32 latest handshake: 8 seconds ago transfer: 1.24 KiB received, 1.08 KiB sent