Setting Up a WireGuard VPN Server on Ubuntu
A WireGuard VPN gives you a fast, modern way to connect securely to a home network, cloud server, or private Ubuntu machine while travelling. It is simpler than many older VPN systems, uses strong cryptography, and performs well on ordinary hardware. Once configured, a laptop or phone can send traffic through your Ubuntu host or reach services on your private network without exposing those services directly to the internet.
This guide covers a practical server setup using Ubuntu Server 22.04 LTS or 24.04 LTS. The same arrangement works on a small home computer, a virtual private server, or an unused desktop. Australian users should pay particular attention to NBN router settings, carrier-grade NAT, changing residential IP addresses, and port forwarding, because those details often determine whether an outside device can reach the VPN.
Choose A Suitable Ubuntu Host
The server needs a stable internet connection and an address that remote clients can use. A low-cost VPS in Sydney, Melbourne, or Brisbane can provide a straightforward public IPv4 address and reliable connectivity. A home server can work just as well, especially if you want secure access to network storage, Home Assistant, or a media library.
Check whether your internet provider places your connection behind carrier-grade NAT, commonly called CGNAT. With CGNAT, the router does not receive a genuinely reachable public IPv4 address, so forwarding UDP port 51820 will not usually work. Some Australian NBN providers offer a public address, sometimes as an optional static or public-IP service. Contact the provider or inspect the router’s WAN address and compare it with a service that displays your public address.
A dynamic public address is manageable with dynamic DNS. A hostname such as vpn.example.net can be updated automatically whenever the home address changes. If your provider supplies native IPv6, WireGuard can also use it, although the firewall and client network must support IPv6 correctly. A VPS avoids most of these home-network complications and is often the quickest choice for a first deployment.
Before changing anything, record the server’s public address, its internet-facing interface, and the private subnet used by your home LAN. The commands below use 10.8.0.0/24 for VPN clients and assume the public network interface is eth0. Ubuntu may instead name it ens3, enp1s0, or something similar.
Prepare Ubuntu And The Firewall
Log in to the server and apply current package updates:
sudo apt update
sudo apt full-upgrade -y
sudo apt install wireguard qrencode ufw -y
Find the default route and interface:
ip route get 1.1.1.1
Look for the device name after dev. Set it as an environment variable for the current shell, replacing eth0 if required:
export WAN_IFACE=eth0
Allow SSH before enabling UFW so that a remote session is not locked out:
sudo ufw allow OpenSSH
sudo ufw allow 51820/udp
WireGuard itself does not need a TCP port. UDP 51820 is the conventional choice, though another unused UDP port can be selected. If the server is behind a home router, forward that UDP port to the Ubuntu machine. Reserve the Ubuntu host’s local address through the router’s DHCP reservation feature, because a changed LAN address would break forwarding.
Enable IPv4 forwarding so the server can pass client traffic towards the internet:
sudo tee /etc/sysctl.d/99-wireguard-forwarding.conf >/dev/null <<'EOF'
net.ipv4.ip_forward=1
EOF
sudo sysctl --system
For a dual-stack network, IPv6 forwarding and IPv6 firewall rules require a separate design. Start with IPv4 unless you have a reason to route IPv6 through the tunnel. A VPN protects traffic between the client and the VPN endpoint; it does not automatically provide anonymity, defeat every tracking system, or make an unsafe endpoint trustworthy.
Create Keys And The Server Interface
WireGuard identifies each peer through a private and public key pair. Keep private keys readable only by their owner and never publish them in screenshots, support requests, or configuration repositories.
Create the server directory and keys:
sudo install -m 700 -d /etc/wireguard
cd /etc/wireguard
sudo sh -c 'umask 077; wg genkey | tee server_private.key | wg pubkey > server_public.key'
sudo cat server_public.key
Copy the displayed public key somewhere safe. The private key stays on the server. Create the initial server configuration:
sudo nano /etc/wireguard/wg0.conf
Add this content, replacing SERVER_PRIVATE_KEY with the output of:
sudo cat /etc/wireguard/server_private.key
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY
SaveConfig = true
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
Change -o eth0 to the actual WAN interface if necessary. The masquerade rule translates VPN client addresses when they access the internet through the server. On a home server, the same rule lets clients use the home connection. Keep the file private:
sudo chmod 600 /etc/wireguard/wg0.conf
The Address value is the internal WireGuard network, not the public address of the server. Every peer must receive a unique address from this range. The server uses 10.8.0.1, while the first client might use 10.8.0.2 and the next 10.8.0.3.
Add A Laptop Or Phone As A Peer
Generate a client key pair on the client device when possible. On another Ubuntu computer, the commands are:
umask 077
wg genkey | tee client_private.key | wg pubkey > client_public.key
cat client_public.key
For Android or iOS, the official WireGuard application can generate a tunnel and display a QR code. Copy the client’s public key and add a peer to /etc/wireguard/wg0.conf on the server:
[Peer]
PublicKey = CLIENT_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32
AllowedIPs on the server identifies which tunnel address belongs to that peer. Use a different /32 address for every phone, tablet, laptop, or remote office. Do not assign the same address to two devices, as both peers would compete for the same traffic.
Create the client configuration on the device:
[Interface]
PrivateKey = CLIENT_PRIVATE_KEY
Address = 10.8.0.2/24
DNS = 1.1.1.1
[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = vpn.example.net:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25
Replace the placeholders with the relevant values. AllowedIPs = 0.0.0.0/0 sends all IPv4 traffic through the VPN, which is useful on public Wi-Fi at airports, hotels, libraries, or cafés in Sydney and Melbourne. If you only need access to the VPN network, use AllowedIPs = 10.8.0.0/24 instead. For access to a home LAN such as 192.168.1.0/24, include that subnet as well.
PersistentKeepalive = 25 helps a phone or laptop behind a router maintain a usable connection. It is particularly helpful when moving between mobile data and Wi-Fi networks. On an Ubuntu client, save the file as /etc/wireguard/wg0.conf and protect it with chmod 600.
Start The Tunnel And Check Connectivity
Bring up the server interface:
sudo systemctl enable --now wg-quick@wg0
sudo systemctl status wg-quick@wg0
Inspect the interface and handshake information:
sudo wg show
ip address show wg0
A newly added peer may show no latest handshake until the client activates its tunnel and sends traffic. Start the client tunnel with the WireGuard application or, on Ubuntu, run:
sudo systemctl enable --now wg-quick@wg0
Check that the client has received the expected VPN address and test the server:
ping -c 3 10.8.0.1
If the client uses a full-tunnel configuration, visit an IP-checking website and confirm that it shows the server’s public address rather than the address of the local network. A server in Sydney should generally give Australian services a familiar Australian source address, although geolocation databases can be inaccurate. Test from a second network, such as a phone’s Telstra, Optus, or Vodafone mobile connection, rather than testing only from the same home Wi-Fi.
When there is no handshake, check the common causes in order: an incorrect endpoint hostname, a missing router port forward, CGNAT, a blocked UDP port, or a mismatched key. On the server, run:
sudo journalctl -u wg-quick@wg0 --no-pager
sudo ss -lunp | grep 51820
sudo ufw status verbose
If the handshake appears but websites do not load, inspect IP forwarding, the masquerade rule, the WAN interface name, and DNS. A successful handshake proves that encrypted packets are reaching the server; it does not prove that the server can route those packets onwards.
Secure And Maintain The VPN
Keep the server and WireGuard package updated through Ubuntu’s normal security maintenance. Private keys should remain out of shell history, cloud notes, public repositories, and shared chat messages. If a phone is lost, remove its peer from the server configuration and reload the interface. A compromised client key cannot be repaired by changing the client’s IP address alone.
Use a separate peer entry for each device rather than sharing one configuration. This makes revocation clear and allows you to see which device last connected. A phone might use 10.8.0.2, a laptop 10.8.0.3, and a tablet 10.8.0.4. Keep a small private inventory of these assignments and the date each key was created.
For a home installation, confirm that the router forwards UDP 51820 to the correct Ubuntu address after firmware updates or network changes. Dynamic DNS should update promptly when an Australian residential IP changes. For a VPS, restrict SSH access where practical, use key-based login, disable password authentication after verifying key access, and monitor system logs.
The final configuration should have a running server, one uniquely addressed peer, a recent handshake, and successful traffic through the chosen route. Activate the tunnel on the client, wait for the handshake, then run ping -c 3 10.8.0.1 and check the public IP from a separate network.