Skip to content

How to install WireGuard on a VPS in 10 minutes ​

WireGuard is a fast and simple VPN protocol built into the Linux kernel. In this guide you set up your own WireGuard server on a VPS and connect a phone or a computer to it. You need a VPS with Ubuntu 22.04, 24.04 or Debian 12 and SSH access.

What you need ​

  • An OBLAKO VPS. The entry plan is enough for a personal VPN, see VPS for VPN.
  • The IP address and root password from the server card in the panel.
  • The WireGuard app on your device: wireguard.com/install.

Step 1. Connect and install WireGuard ​

Connect via SSH and run:

bash
apt update && apt upgrade -y
apt install -y wireguard qrencode

Step 2. Generate keys ​

The server and every device get their own key pair. Create keys for the server and the first client:

bash
cd /etc/wireguard
umask 077
wg genkey | tee server.key | wg pubkey > server.pub
wg genkey | tee client1.key | wg pubkey > client1.pub

Step 3. Find the network interface name ​

bash
ip route list default

The word after dev is the interface name, for example eth0 or ens3. You need it in the configuration.

Step 4. Configure the server ​

Create /etc/wireguard/wg0.conf. Replace eth0 with your interface name and take the key values from cat server.key and cat client1.pub. Only the highlighted lines need changes:

ini
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = CONTENTS_OF_server.key
PostUp = iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE; iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT
PostDown = iptables -t nat -D POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE; iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT

[Peer]
PublicKey = CONTENTS_OF_client1.pub
AllowedIPs = 10.8.0.2/32

Enable packet forwarding and start WireGuard:

bash
echo 'net.ipv4.ip_forward=1' > /etc/sysctl.d/99-wireguard.conf
sysctl --system
systemctl enable --now wg-quick@wg0

If the UFW firewall is enabled, open the port:

bash
ufw allow 51820/udp

Step 5. Create the client configuration ​

Create /etc/wireguard/client1.conf with the client key (cat client1.key), the server public key (cat server.pub) and your VPS IP in the highlighted lines:

ini
[Interface]
PrivateKey = CONTENTS_OF_client1.key
Address = 10.8.0.2/32
DNS = 1.1.1.1

[Peer]
PublicKey = CONTENTS_OF_server.pub
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25

Step 6. Connect your device ​

Phone. Show the configuration as a QR code and scan it in the WireGuard app:

bash
qrencode -t ansiutf8 < /etc/wireguard/client1.conf

Computer. Copy the contents of client1.conf to a file on your computer and import it in the WireGuard app.

Turn the tunnel on and check that your public IP is now the server IP.

Adding another device ​

  1. Create client2.key and client2.pub as in step 2.
  2. Add another [Peer] block to wg0.conf with AllowedIPs = 10.8.0.3/32.
  3. Create client2.conf with the address 10.8.0.3/32.
  4. Restart the service: systemctl restart wg-quick@wg0.

Troubleshooting ​

SymptomWhat to check
No handshake (wg show has no latest handshake)Port 51820/udp is open, the keys and the Endpoint IP are correct
Tunnel is up but no internetip_forward is enabled and the interface name in PostUp is right
Unstable on some networksTry the AmneziaWG protocol through the AmneziaVPN app

Personal use only

OBLAKO allows a personal VPN for yourself, your family or a small team. Public VPNs and reselling access are not allowed, see the acceptable use policy.