WireGuard is an open-source virtual private network (VPN) that applies advanced modern cryptography to safeguard communication between servers and clients. It is lightweight, efficient, and has a minimal codebase focusing on essential features, providing superior performance and security compared to other VPNs such as OpenVPN.
This guide details how to install and configure WireGuard VPN on Ubuntu 24.04 to create secure, encrypted network tunnels.
Prerequisites
- Deploy an Ubuntu 24.04 server to use as the WireGuard VPN host.
- Access the server through SSH as a non-root user with sudo privileges.
- Update the server packages to ensure it’s current.
Matching infrastructure at centron
Ubuntu servers without your own hardware: ccloud³ VMs with full root access from €3.12 per month, billed by the hour and ready in seconds. Rent a cloud server →
Install WireGuard
WireGuard is included in Ubuntu 24.04’s default APT repositories. Follow the steps below to install the latest version and configure it to launch at system startup.
Install WireGuard
$ sudo apt install wireguard -yCheck Installed Version
$ sudo wg --versionYour output should resemble:
wireguard-tools v1.0.20210914 - https://git.zx2c4.com/wireguard-tools/
Configure WireGuard
WireGuard uses Cryptokey Routing to establish VPN tunnels through validation of public keys tied to specific IPs. A valid setup includes both a private and public key linked to the network interface. Follow these steps to configure your WireGuard interface and create the necessary key pairs.
Generate the Private Key
$ sudo wg genkey | sudo tee /etc/wireguard/server_private.keyExample output:
UOO//MO2GCC+5hHOz91YCP60/Zv/cnSskEH2j4eRPXo=
Adjust File Permissions
$ sudo chmod 600 /etc/wireguard/server_private.keyGenerate the Public Key
$ sudo cat /etc/wireguard/server_private.key | wg pubkey | sudo tee /etc/wireguard/server_public.keyExample output:
W+l7Uapd98bsNhN1g3Hs4iTCfKzcV03KNwhDPFgzqR4=
Check Network Interfaces
$ ip aLocate the main network interface, e.g., enp1s0 with IP 192.0.2.161. WireGuard uses this interface to route and translate traffic to the Internet.
Create WireGuard Configuration File
$ sudo nano /etc/wireguard/wg0.confInsert the following configuration (replace keys and interface as required):
[Interface]
Address = 10.8.0.1/24
SaveConfig = true
PrivateKey = UOO//MO2GCC+5hHOz91YCP60/Zv/cnSskEH2j4eRPXo=
PostUp = ufw route allow in on wg0 out on enp1s0
PostUp = iptables -t nat -I POSTROUTING -o enp1s0 -j MASQUERADE
PreDown = ufw route delete allow in on wg0 out on enp1s0
PreDown = iptables -t nat -D POSTROUTING -o enp1s0 -j MASQUERADE
ListenPort = 51820This configuration assigns a private IP (10.8.0.1), enables NAT routing, defines firewall and iptables rules, and sets the WireGuard listening port.
Generate Client Configurations
Each client must have a public key in the WireGuard configuration to establish a connection. The steps below guide you in creating a new client setup.
Create Client Keys
$ sudo wg genkey | sudo tee /etc/wireguard/client1_private.key$ sudo cat /etc/wireguard/client1_private.key | wg pubkey | sudo tee /etc/wireguard/client1_public.keyCreate Client Configuration
$ sudo nano /etc/wireguard/client1.confInsert the following content, replacing placeholders accordingly:
[Interface]
PrivateKey = KBUxCUqNEJqN3DBO5xu2kiBQFT8Gv46Kkqu6OIKZu3Q=
Address = 10.8.0.2/24
DNS = 8.8.8.8
[Peer]
PublicKey = W+l7Uapd98bsNhN1g3Hs4iTCfKzcV03KNwhDPFgzqR4=
AllowedIPs = 0.0.0.0/0
Endpoint = 192.0.2.161:51820
PersistentKeepalive = 15This setup allows a client to connect via IP 10.8.0.2, defining the server key, endpoint, and persistent connection interval.
Add Client to Server Configuration
$ sudo nano /etc/wireguard/wg0.confAppend the following section:
[Peer]
PublicKey = xZB9I6953ebGqWVLCR7L6yJw7YJi0shJ+Sub9gfUFVU=
AllowedIPs = 10.8.0.2/32Manage the WireGuard Service
Systemd handles WireGuard processes. The wg-quick utility provides management commands for interfaces.
$ sudo systemctl start wg-quick@wg0.service$ sudo systemctl enable wg-quick@wg0.service$ sudo systemctl status wg-quick@wg0.serviceUse this command to view the current tunnel status:
$ sudo wg show wg0Set Up Firewall Rules
UFW is typically active by default. Configure it to allow UDP port 51820 and enable IP forwarding for proper routing.
$ sudo ufw allow 22 && sudo ufw enable
$ sudo ufw allow 51820/udp
$ sudo ufw reloadEnable IP Forwarding
$ echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.conf
$ sudo sysctl -pApply NAT Rules
$ sudo iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o enp1s0 -j MASQUERADE
$ sudo iptables-save | sudo tee /etc/iptables/rules.v4Connect Clients to WireGuard VPN
Use your generated client configuration to connect and test tunnel access using Ping.
$ scp linuxuser@wireguard-server-ip:client1.conf .Test Connectivity
$ ping -c 4 10.8.0.1Expected output:
4 packets transmitted, 4 received, 0% packet loss
Conclusion
You have successfully installed and configured WireGuard VPN on an Ubuntu 24.04 server, set up client connections, and established secure tunnels. You can create additional interfaces with separate subnets for different user groups. Refer to the official WireGuard documentation for advanced configuration details.
Testen Sie Ihr Setup auf ccloud³
Registrieren Sie sich in der ccloud³ und erhalten Sie 200 € Startguthaben für Ihr Projekt – z. B. für eine PostgreSQL-VM mit automatischen Backups.