Set Up a WireGuard VPN on a VPS
WireGuard is the modern, fast, and secure VPN protocol that outperforms OpenVPN and IPSec. Here’s how to deploy it on your Linux VPS in minutes.
1. Why WireGuard?
WireGuard uses state-of-the-art cryptography like ChaCha20 and Curve25519. It’s lightweight, easy to configure, and extremely fast — perfect for VPS deployments.
2. Requirements
- A Debian or Ubuntu VPS
- Root access or sudo privileges
- Public IP or domain name
3. Install WireGuard
sudo apt update
sudo apt install wireguard qrencode net-tools4. Generate keys
umask 077
wg genkey | tee /etc/wireguard/privatekey | wg pubkey > /etc/wireguard/publickeySave both server keys for future use.
5. Configure the server
[Interface]
Address = 10.6.0.1/24
ListenPort = 51820
PrivateKey = (server_private_key)
SaveConfig = true
PostUp = ufw route allow in on wg0 out on eth0
PostDown = ufw route delete allow in on wg0 out on eth0sudo systemctl enable wg-quick@wg0
sudo systemctl start wg-quick@wg06. Add a client
wg genkey | tee client-privatekey | wg pubkey > client-publickeyEdit /etc/wireguard/wg0.conf and add:
[Peer]
PublicKey = (client_public_key)
AllowedIPs = 10.6.0.2/327. Client configuration
[Interface]
PrivateKey = (client_private_key)
Address = 10.6.0.2/24
DNS = 1.1.1.1
[Peer]
PublicKey = (server_public_key)
Endpoint = your-vps-ip:51820
AllowedIPs = 0.0.0.0/0, ::/0Generate a QR code for mobile setup:
qrencode -t ansiutf8 < client.conf8. Enable routing
sudo sysctl -w net.ipv4.ip_forward=1
sudo sysctl -w net.ipv6.conf.all.forwarding=1Edit /etc/sysctl.conf to make it permanent.
9. Secure with UFW
sudo ufw allow 51820/udp
sudo ufw enable10. Test your VPN
Connect from your client device and check your IP using whatismyip.com. If it shows your VPS IP, your VPN is running successfully.
Conclusion
A WireGuard VPN gives you privacy, security, and speed — without relying on commercial providers. Host your own VPN today at https://vps1dollar.com.
Also read: How to Choose a VPS