How to install WireGuard on a VPS in 10 minutes
WireGuard is a fast and simple VPN protocol built into the Linux kernel. In this guide you set up your own WireGuard server on a VPS and connect a phone or a computer to it. You need a VPS with Ubuntu 22.04, 24.04 or Debian 12 and SSH access.
What you need
- An OBLAKO VPS. The entry plan is enough for a personal VPN, see VPS for VPN.
- The IP address and root password from the server card in the panel.
- The WireGuard app on your device: wireguard.com/install.
Step 1. Connect and install WireGuard
Connect via SSH and run:
apt update && apt upgrade -y
apt install -y wireguard qrencodeStep 2. Generate keys
The server and every device get their own key pair. Create keys for the server and the first client:
cd /etc/wireguard
umask 077
wg genkey | tee server.key | wg pubkey > server.pub
wg genkey | tee client1.key | wg pubkey > client1.pubStep 3. Find the network interface name
ip route list defaultThe word after dev is the interface name, for example eth0 or ens3. You need it in the configuration.
Step 4. Configure the server
Create /etc/wireguard/wg0.conf. Replace eth0 with your interface name and take the key values from cat server.key and cat client1.pub. Only the highlighted lines need changes:
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = CONTENTS_OF_server.key
PostUp = iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE; iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT
PostDown = iptables -t nat -D POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE; iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT
[Peer]
PublicKey = CONTENTS_OF_client1.pub
AllowedIPs = 10.8.0.2/32Enable packet forwarding and start WireGuard:
echo 'net.ipv4.ip_forward=1' > /etc/sysctl.d/99-wireguard.conf
sysctl --system
systemctl enable --now wg-quick@wg0If the UFW firewall is enabled, open the port:
ufw allow 51820/udpStep 5. Create the client configuration
Create /etc/wireguard/client1.conf with the client key (cat client1.key), the server public key (cat server.pub) and your VPS IP in the highlighted lines:
[Interface]
PrivateKey = CONTENTS_OF_client1.key
Address = 10.8.0.2/32
DNS = 1.1.1.1
[Peer]
PublicKey = CONTENTS_OF_server.pub
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25Step 6. Connect your device
Phone. Show the configuration as a QR code and scan it in the WireGuard app:
qrencode -t ansiutf8 < /etc/wireguard/client1.confComputer. Copy the contents of client1.conf to a file on your computer and import it in the WireGuard app.
Turn the tunnel on and check that your public IP is now the server IP.
Adding another device
- Create
client2.keyandclient2.pubas in step 2. - Add another
[Peer]block towg0.confwithAllowedIPs = 10.8.0.3/32. - Create
client2.confwith the address10.8.0.3/32. - Restart the service:
systemctl restart wg-quick@wg0.
Troubleshooting
| Symptom | What to check |
|---|---|
No handshake (wg show has no latest handshake) | Port 51820/udp is open, the keys and the Endpoint IP are correct |
| Tunnel is up but no internet | ip_forward is enabled and the interface name in PostUp is right |
| Unstable on some networks | Try the AmneziaWG protocol through the AmneziaVPN app |
Personal use only
OBLAKO allows a personal VPN for yourself, your family or a small team. Public VPNs and reselling access are not allowed, see the acceptable use policy.