On this page
What you need before you start
WireGuard is both a VPN protocol and a family of free, open-source apps. The app itself contains no servers. It connects to whatever server your configuration file describes, so the same app works with any provider that supports WireGuard.
A configuration file is a short text file ending in .conf. It holds your private key, the server's public key and address, the private address your device uses inside the tunnel and the DNS server to use while connected. Most providers can also show it as a QR code, which is the fastest way to set up a phone.
With BoltVeil, sign in, open Setup in your dashboard, choose a location and pick WireGuard. You can download the .conf file or show its QR code on screen. Each file points at one server, so save one for each location you use often. The download page links to the official app for every platform, and the pricing page lists how many devices each plan covers.
[Interface]
PrivateKey = <your private key: keep it secret>
Address = 10.8.0.2/32
DNS = 10.8.0.1
[Peer]
PublicKey = <the server's public key>
Endpoint = <server address>:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25You rarely need to edit anything, but it helps to know what the lines do. AllowedIPs = 0.0.0.0/0, ::/0 sends all IPv4 and IPv6 traffic into the tunnel. DNS makes your device look up site names through the VPN instead of through your internet provider. PersistentKeepalive keeps the tunnel reachable behind home routers and mobile networks that close idle connections.
Windows 10 and 11
- Download WireGuard for Windows from the official site, wireguard.com/install, and run the installer. Avoid look-alike apps promoted in search ads.
- Open WireGuard, click Import tunnel(s) from file and pick the
.confyou downloaded. The tunnel appears in the list on the left. - Click Edit. If you see Block untunneled traffic (kill-switch), tick it and save. While the tunnel is active, Windows can then reach the internet only through the VPN.
- Click Activate. The status changes to Active and the data counters start moving.
The kill-switch option only appears when the configuration sends all traffic through the tunnel, with 0.0.0.0/0 in AllowedIPs. If you change that line to route only some traffic through the VPN, the option disappears, because Windows can no longer tell a leak from traffic you meant to send outside.
WireGuard needs administrator rights to install on Windows and, by default, to switch tunnels. On a work laptop you may not have them, and that is usually deliberate. Read the section on managed devices in our school and work network guide before trying to get around it.
macOS
- Install WireGuard from the Mac App Store. The publisher is WireGuard Development Team.
- Open it from the menu bar, choose Import tunnel(s) from file and select the
.conf. When macOS asks whether to allow the VPN configuration, click Allow. - Select the tunnel and click Activate. From then on you can switch tunnels on and off from the menu bar icon.
Two settings in the tunnel's Edit view are worth a look. On-Demand starts the tunnel by itself whenever you join Wi-Fi or Ethernet, so you do not have to remember. Exclude private IPs keeps printers, NAS drives and other devices on your local network reachable while the VPN is on.
iPhone, iPad and Android
On a phone, the QR code is the fastest route: open the Setup page on a computer and scan the code with your phone. Nothing needs to be downloaded, emailed or copied.
iPhone and iPad
- Install WireGuard from the App Store.
- Tap Add a tunnel (or the plus button) and choose Create from QR code.
- Scan the code, give the tunnel a short name and allow iOS to add the VPN configuration.
- Switch the tunnel on. A VPN badge appears in the status bar.
In the tunnel's settings, On-Demand Activation can start the VPN automatically on mobile data, Wi-Fi or both, with exceptions for networks you trust, such as your home Wi-Fi.
Android
- Install WireGuard from Google Play. The publisher is WireGuard Development Team.
- Tap the plus button and choose Scan from QR code, or Import from file or archive if you saved the
.confon the phone. - Name the tunnel and switch it on. Android asks once for permission to set up a VPN connection.
For a real kill switch, use Android's own setting rather than an app toggle. Open Settings, then Network & internet, then VPN, tap the gear next to WireGuard and turn on Always-on VPN and Block connections without VPN. The menu names differ slightly between phone makers.
Linux
WireGuard has been part of the Linux kernel since version 5.6, so on any current distribution you only need the small wireguard-tools package and the wg-quick helper that comes with it.
# Debian, Ubuntu and their derivatives
sudo apt install wireguard-tools
# Fedora
sudo dnf install wireguard-tools
# Copy the file under a short name (15 characters at most)
sudo cp ~/Downloads/boltveil-de-frankfurt.conf /etc/wireguard/bv-de.conf
sudo chmod 600 /etc/wireguard/bv-de.conf
# Connect, check, disconnect
sudo wg-quick up bv-de
sudo wg show
sudo wg-quick down bv-de
# Connect at every boot
sudo systemctl enable --now wg-quick@bv-deIf wg-quick stops with resolvconf: command not found, your system is missing the helper it uses to set DNS. Install your distribution's openresolv or resolvconf package, or skip wg-quick and import the file into NetworkManager with nmcli connection import type wireguard file /etc/wireguard/bv-de.conf. The tunnel then appears in your desktop's network menu like any other connection.
Routers, TVs and game consoles
Most smart TVs, game consoles and streaming sticks cannot run a WireGuard app. The usual answer is to run WireGuard on your router, so every device behind it uses the tunnel without any setup of its own.
- OpenWrt: install the
luci-proto-wireguardpackage, create a WireGuard interface and copy the values from your config file, or use the import option that recent versions offer. - GL.iNet travel routers: open VPN, then WireGuard Client, and upload or paste the config file. It is also a neat way to protect every device on hotel Wi-Fi at once.
- pfSense, OPNsense and many recent ASUS routers: a WireGuard client is available as a package or built into the firmware, and its fields map one to one onto the lines of the config file.
Two things to know. To the VPN server, a router is a single connection, however many devices sit behind it. And budget routers have slow processors, so they may not reach your full internet speed through the tunnel. WireGuard is far lighter than OpenVPN, which is why it is the protocol to pick on a router.
Check that it works
- With the tunnel off, note your public IP address and location. The IP check on our home page shows what websites can see about you.
- Switch the tunnel on and check again. The address and location should now belong to the server you chose.
- Run a DNS leak test and a WebRTC test. Our DNS and WebRTC leak guide explains how to read the results and fix anything that shows up.
- In the WireGuard app, look at Latest handshake. While you are using the internet it should refresh every couple of minutes. If it never appears, your device cannot reach the server.
Common problems and how to fix them
| Symptom | Likely cause | Fix |
|---|---|---|
| Connected, but no websites load | The network blocks the UDP traffic WireGuard uses, or DNS is not answering | Try another location. On hotel, train or guest Wi-Fi that allows VPNs, switch to OpenVPN over TCP, our firewall mode |
| No handshake at all | Outdated or damaged config file, or UDP is blocked | Download the file again from your dashboard and import it again |
| Works on Wi-Fi but not on mobile data, or the reverse | Some networks use a smaller packet size | Add MTU = 1280 under [Interface] and reconnect |
resolvconf: command not found on Linux | The DNS helper is missing | Install openresolv or import the file with nmcli |
| Printer or NAS unreachable | All traffic, including your local network, goes into the tunnel | On macOS, iOS and Android, tick Exclude private IPs in the tunnel settings |
| Slow speeds | A distant or busy server | Pick a closer location from the servers page |
If the network you are on blocks VPNs on purpose, for example at work or at school, read our guide on using a VPN on a school or work network before you try another protocol. The rules of that network still apply to you.