Skip to content
Guide

How to set up WireGuard on any device

WireGuard is the quickest way to put a VPN on almost anything you own. You need two things: the free official WireGuard app and a configuration file from your VPN provider. This guide covers every major platform, the settings worth changing and the errors people actually run into.

8 min read

What you need before you start

WireGuard is both a VPN protocol and a family of free, open-source apps. The app itself contains no servers. It connects to whatever server your configuration file describes, so the same app works with any provider that supports WireGuard.

A configuration file is a short text file ending in .conf. It holds your private key, the server's public key and address, the private address your device uses inside the tunnel and the DNS server to use while connected. Most providers can also show it as a QR code, which is the fastest way to set up a phone.

With BoltVeil, sign in, open Setup in your dashboard, choose a location and pick WireGuard. You can download the .conf file or show its QR code on screen. Each file points at one server, so save one for each location you use often. The download page links to the official app for every platform, and the pricing page lists how many devices each plan covers.

INI
[Interface]
PrivateKey = <your private key: keep it secret>
Address = 10.8.0.2/32
DNS = 10.8.0.1

[Peer]
PublicKey = <the server's public key>
Endpoint = <server address>:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

You rarely need to edit anything, but it helps to know what the lines do. AllowedIPs = 0.0.0.0/0, ::/0 sends all IPv4 and IPv6 traffic into the tunnel. DNS makes your device look up site names through the VPN instead of through your internet provider. PersistentKeepalive keeps the tunnel reachable behind home routers and mobile networks that close idle connections.

Windows 10 and 11

  1. Download WireGuard for Windows from the official site, wireguard.com/install, and run the installer. Avoid look-alike apps promoted in search ads.
  2. Open WireGuard, click Import tunnel(s) from file and pick the .conf you downloaded. The tunnel appears in the list on the left.
  3. Click Edit. If you see Block untunneled traffic (kill-switch), tick it and save. While the tunnel is active, Windows can then reach the internet only through the VPN.
  4. Click Activate. The status changes to Active and the data counters start moving.

The kill-switch option only appears when the configuration sends all traffic through the tunnel, with 0.0.0.0/0 in AllowedIPs. If you change that line to route only some traffic through the VPN, the option disappears, because Windows can no longer tell a leak from traffic you meant to send outside.

WireGuard needs administrator rights to install on Windows and, by default, to switch tunnels. On a work laptop you may not have them, and that is usually deliberate. Read the section on managed devices in our school and work network guide before trying to get around it.

macOS

  1. Install WireGuard from the Mac App Store. The publisher is WireGuard Development Team.
  2. Open it from the menu bar, choose Import tunnel(s) from file and select the .conf. When macOS asks whether to allow the VPN configuration, click Allow.
  3. Select the tunnel and click Activate. From then on you can switch tunnels on and off from the menu bar icon.

Two settings in the tunnel's Edit view are worth a look. On-Demand starts the tunnel by itself whenever you join Wi-Fi or Ethernet, so you do not have to remember. Exclude private IPs keeps printers, NAS drives and other devices on your local network reachable while the VPN is on.

iPhone, iPad and Android

On a phone, the QR code is the fastest route: open the Setup page on a computer and scan the code with your phone. Nothing needs to be downloaded, emailed or copied.

iPhone and iPad

  1. Install WireGuard from the App Store.
  2. Tap Add a tunnel (or the plus button) and choose Create from QR code.
  3. Scan the code, give the tunnel a short name and allow iOS to add the VPN configuration.
  4. Switch the tunnel on. A VPN badge appears in the status bar.

In the tunnel's settings, On-Demand Activation can start the VPN automatically on mobile data, Wi-Fi or both, with exceptions for networks you trust, such as your home Wi-Fi.

Android

  1. Install WireGuard from Google Play. The publisher is WireGuard Development Team.
  2. Tap the plus button and choose Scan from QR code, or Import from file or archive if you saved the .conf on the phone.
  3. Name the tunnel and switch it on. Android asks once for permission to set up a VPN connection.

For a real kill switch, use Android's own setting rather than an app toggle. Open Settings, then Network & internet, then VPN, tap the gear next to WireGuard and turn on Always-on VPN and Block connections without VPN. The menu names differ slightly between phone makers.

Linux

WireGuard has been part of the Linux kernel since version 5.6, so on any current distribution you only need the small wireguard-tools package and the wg-quick helper that comes with it.

BASH
# Debian, Ubuntu and their derivatives
sudo apt install wireguard-tools
# Fedora
sudo dnf install wireguard-tools

# Copy the file under a short name (15 characters at most)
sudo cp ~/Downloads/boltveil-de-frankfurt.conf /etc/wireguard/bv-de.conf
sudo chmod 600 /etc/wireguard/bv-de.conf

# Connect, check, disconnect
sudo wg-quick up bv-de
sudo wg show
sudo wg-quick down bv-de

# Connect at every boot
sudo systemctl enable --now wg-quick@bv-de

If wg-quick stops with resolvconf: command not found, your system is missing the helper it uses to set DNS. Install your distribution's openresolv or resolvconf package, or skip wg-quick and import the file into NetworkManager with nmcli connection import type wireguard file /etc/wireguard/bv-de.conf. The tunnel then appears in your desktop's network menu like any other connection.

Routers, TVs and game consoles

Most smart TVs, game consoles and streaming sticks cannot run a WireGuard app. The usual answer is to run WireGuard on your router, so every device behind it uses the tunnel without any setup of its own.

  • OpenWrt: install the luci-proto-wireguard package, create a WireGuard interface and copy the values from your config file, or use the import option that recent versions offer.
  • GL.iNet travel routers: open VPN, then WireGuard Client, and upload or paste the config file. It is also a neat way to protect every device on hotel Wi-Fi at once.
  • pfSense, OPNsense and many recent ASUS routers: a WireGuard client is available as a package or built into the firmware, and its fields map one to one onto the lines of the config file.

Two things to know. To the VPN server, a router is a single connection, however many devices sit behind it. And budget routers have slow processors, so they may not reach your full internet speed through the tunnel. WireGuard is far lighter than OpenVPN, which is why it is the protocol to pick on a router.

Check that it works

  1. With the tunnel off, note your public IP address and location. The IP check on our home page shows what websites can see about you.
  2. Switch the tunnel on and check again. The address and location should now belong to the server you chose.
  3. Run a DNS leak test and a WebRTC test. Our DNS and WebRTC leak guide explains how to read the results and fix anything that shows up.
  4. In the WireGuard app, look at Latest handshake. While you are using the internet it should refresh every couple of minutes. If it never appears, your device cannot reach the server.

Common problems and how to fix them

SymptomLikely causeFix
Connected, but no websites loadThe network blocks the UDP traffic WireGuard uses, or DNS is not answeringTry another location. On hotel, train or guest Wi-Fi that allows VPNs, switch to OpenVPN over TCP, our firewall mode
No handshake at allOutdated or damaged config file, or UDP is blockedDownload the file again from your dashboard and import it again
Works on Wi-Fi but not on mobile data, or the reverseSome networks use a smaller packet sizeAdd MTU = 1280 under [Interface] and reconnect
resolvconf: command not found on LinuxThe DNS helper is missingInstall openresolv or import the file with nmcli
Printer or NAS unreachableAll traffic, including your local network, goes into the tunnelOn macOS, iOS and Android, tick Exclude private IPs in the tunnel settings
Slow speedsA distant or busy serverPick a closer location from the servers page

If the network you are on blocks VPNs on purpose, for example at work or at school, read our guide on using a VPN on a school or work network before you try another protocol. The rules of that network still apply to you.

Frequently asked questions

Is WireGuard free?

Yes. The protocol and the official apps are free and open source. What you pay a VPN provider for is the servers and bandwidth behind the config file. BoltVeil also lets you earn premium days without paying; see how the free plan works.

Does WireGuard have a kill switch?

The protocol does not, but platforms do: Block untunneled traffic in the Windows app, and Always-on VPN with Block connections without VPN on Android. On iPhone and Mac, On-Demand brings the tunnel back automatically, which helps, but it is not a strict kill switch.

Is WireGuard secure?

Yes. It uses a small, fixed set of modern cryptography (Curve25519, ChaCha20-Poly1305 and BLAKE2s), its code base is small enough to review, and it has shipped in the Linux kernel since 2020. Its security still depends on keeping your config file private.

Should I use WireGuard or OpenVPN?

WireGuard by default: it is faster, connects almost instantly and copes well with switching between Wi-Fi and mobile data. Use OpenVPN over TCP, our firewall mode, only when a network stops WireGuard and VPNs are allowed there. The protocol guide compares them in detail.

Where do I find the list of locations?

The servers page lists every current location. Each config file is for one server, so download a new file when you want to connect somewhere else.

Your IP, hidden in minutes.

Create your account, pick a country and connect. Pay less, or earn it free.