WireGuard VPN Configuration Examples
Overview
This directory contains example WireGuard VPN configurations for the SAW implementation.
Files
config/wireguard/
├── wg0.conf.example # Example WireGuard configuration
├── README.md # This file
└── setup-vpn.sh # VPN setup script (optional)
Quick Start
1. Generate Keys
# Generate server keys
wg genkey | tee server_private.key | wg pubkey > server_public.key
# Generate client keys
wg genkey | tee client_private.key | wg pubkey > client_public.key
2. Configure Server
Create /etc/wireguard/wg0.conf on VPN server:
[Interface]
PrivateKey = <server_private_key>
Address = 10.0.0.1/24
ListenPort = 51820
[Peer]
PublicKey = <client_public_key>
AllowedIPs = 10.0.0.2/32
3. Configure Client (SAW)
Copy the example config and update with your keys:
cp config/wireguard/wg0.conf.example /etc/wireguard/wg0.conf
# Edit the configuration
nano /etc/wireguard/wg0.conf
4. Start VPN
# Start WireGuard
sudo wg-quick up wg0
# Check status
sudo wg show
# Enable auto-start
sudo systemctl enable wg-quick@wg0
Example Configuration
wg0.conf.example
[Interface]
# Your WireGuard private key (generated with: wg genkey)
PrivateKey = YOUR_PRIVATE_KEY_HERE
# VPN interface IP and subnet
Address = 10.0.0.2/24
# DNS servers (should be VPN gateway)
DNS = 10.0.0.1
[Peer]
# VPN server's public key
PublicKey = YOUR_SERVER_PUBLIC_KEY_HERE
# VPN server's endpoint (IP:port)
Endpoint = vpn.example.com:51820
# Which IPs to route through VPN (0.0.0.0/0 = all traffic)
AllowedIPs = 0.0.0.0/0, ::/0
# Keep connection alive (optional)
PersistentKeepalive = 25
Configuration Parameters Explained
[Interface] Section
| Parameter | Description | Example |
|---|---|---|
PrivateKey |
Your WireGuard private key | Generated with wg genkey |
Address |
VPN interface IP and subnet | 10.0.0.2/24 |
ListenPort |
Port to listen on (server only) | 51820 |
DNS |
DNS servers to use | 10.0.0.1 |
[Peer] Section
| Parameter | Description | Example |
|---|---|---|
PublicKey |
VPN server's public key | Generated on server |
Endpoint |
VPN server address and port | vpn.example.com:51820 |
AllowedIPs |
IPs to route through VPN | 0.0.0.0/0, ::/0 |
PersistentKeepalive |
Keep connection alive (optional) | 25 |
Security Considerations
Key Management
-
Generate keys securely
- Use
wg genkey(cryptographically secure) - Never share private keys
- Store keys in encrypted storage
- Use
-
Use strong encryption
- WireGuard uses ChaCha20-Poly1305 (default)
- Curve25519 key exchange (default)
- No weak algorithms
-
Restrict AllowedIPs
- Only allow necessary subnets
- Use
/32for single IPs - Avoid
0.0.0.0/0if not needed
Network Security
-
Firewall configuration
- Allow WireGuard port (UDP 51820)
- Block other ports
- Implement egress filtering
-
DNS security
- Use VPN gateway DNS
- Block external DNS
- Consider DNS-over-TLS
-
Keep-alive settings
- Use
PersistentKeepalivefor NAT traversal - Set appropriate interval (25 seconds recommended)
- Disable if not needed
- Use
Troubleshooting
VPN Not Connecting
# Check WireGuard status
sudo wg show
# Check configuration
sudo wg-quick diff wg0.conf
# Check logs
sudo journalctl -u wg-quick@wg0
# Test connectivity
ping -I wg0 <server-ip>
DNS Not Working
# Check DNS configuration
cat /etc/resolv.conf
# Test DNS resolution
nslookup example.com
# Check firewall
sudo firewall-cmd --list-all
Routing Issues
# Check routing table
ip route show
# Check WireGuard routes
ip route show table 51820
# Test routing
ping -I wg0 <external-ip>
Advanced Configuration
Split Tunneling
Route only specific traffic through VPN:
[Peer]
# Only route corporate network
AllowedIPs = 192.168.1.0/24, 10.0.0.0/8
Multi-Hop VPN
Chain multiple VPN servers:
[Peer]
# First hop
PublicKey = <first_hop_public_key>
Endpoint = <first_hop_endpoint>
AllowedIPs = 10.1.0.0/24
[Peer]
# Second hop (behind first hop)
PublicKey = <second_hop_public_key>
Endpoint = <second_hop_endpoint>
AllowedIPs = 10.2.0.0/24
Load Balancing
Multiple servers for redundancy:
[Peer]
PublicKey = <server1_public_key>
Endpoint = <server1_ip>:51820
AllowedIPs = 10.0.0.0/24
[Peer]
PublicKey = <server2_public_key>
Endpoint = <server2_ip>:51820
AllowedIPs = 10.0.0.0/24
References
Support
For WireGuard configuration help:
- Check logs:
sudo journalctl -u wg-quick@wg0 - Verify config:
sudo wg-quick diff wg0.conf - Test connectivity:
ping -I wg0 <server-ip>