Skip to content

WireGuard

WireGuard

x86-64 arm64 ยท ๐Ÿณ Docker ยท Documentation ยท http://<your.IP>:51820

WireGuard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN. WireGuard is designed as a general purpose VPN for running on embedded interfaces and super computers alike, fit for many different circumstances. Initially released for the Linux kernel, it is now cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable. Regarded as the most secure, easiest to use, and simplest VPN solution in the industry.

Install from armbian-config โ†’ Software โ†’ VPN โ†’ WireGuard

WireGuard VPN server
armbian-config --cmd WRG001
  1. Launch armbian-config --api module_wireguard server.

  2. When prompted, enter a comma-separated list of peer names (e.g., laptop,phone,router).

  3. Peer configuration files will be created in

    Text Only
    /armbian/wireguard/config/wg_confs/peer_laptop.conf
    
  4. Scan the QR code (for mobile) or transfer .conf to your client system.

  5. Connect the client using the configuration.

  1. Launch armbian-config --api module_wireguard client.

  2. You will be asked to edit or paste a valid WireGuard configuration.

  3. Provide the client configuration in this format:

Bash
[Interface]
Address = 10.13.13.2/32
PrivateKey = <your-private-key>
DNS = 1.1.1.1

[Peer]
PublicKey = <server-public-key>
Endpoint = your.server.com:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25
  1. The configuration will be saved to:

    Text Only
    /armbian/wireguard/config/wg_confs/client.conf
    
  2. When prompted, enter the local LAN subnets you wish to route via VPN (e.g., 10.0.10.0/24,192.168.0.0/16).

  3. The VPN container will be started and routing rules will be generated accordingly.

  4. Routing will be restored automatically on boot via systemd service.

Remember to open/forward the port 51820 (UDP) through NAT on your router.

  • Install directory: /armbian/wireguard
  • Site configuration directory: /armbian/wireguard/config
Bash
docker logs -f wireguard

All armbian-config commands

Action Command
Install armbian-config --api module_wireguard install
WireGuard VPN client armbian-config --api module_wireguard client
WireGuard VPN server armbian-config --api module_wireguard server
WireGuard remove armbian-config --api module_wireguard remove
WireGuard purge with data folder armbian-config --api module_wireguard purge
WireGuard VPN server QR codes for clients armbian-config --api module_wireguard qrcode
Status armbian-config --api module_wireguard status
Help armbian-config --api module_wireguard help

Part of Armbian’s Virtual Private Network tools software.