By Eric L.
09/08/2026 · 7 MIN READ

Setting up WireGuard takes a few minutes on any platform because the whole configuration is about ten lines, and on a phone it's a QR code.

The official apps exist for Windows, macOS, iOS, Android and Linux, and most routers that can run a VPN client support it. This guide explains what each line means, walks through every platform, and ends with the handful of things that go wrong. If you want to know how WireGuard compares to other protocols first, that is in WireGuard vs OpenVPN.

FROM CONFIG TO CONNECTED, ON ANY PLATFORMSTEP 1Get the config.conf file or QR codefrom your providerSTEP 2Import itfile: Import Tunnelphone: scan the QRSTEP 3Activateallow the VPN requestwhen the system asksSTEP 4Checkhandshake shows timeWhat Is My IP: serverThe file or QR code comes ready to use: nothing to edit.
Whatever the device, setup is the same four steps, and the last one is the check.

WireGuard config file, line by line

[Interface]
PrivateKey = your device's private key
Address = 10.0.0.2/32
DNS = 10.0.0.1

[Peer]
PublicKey = the server's public key
Endpoint = server address:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
  • PrivateKey: your key, never leaves the device; leaking it equals leaking the account.
  • Address: your device's address inside the tunnel.
  • DNS: the resolver used once the tunnel is up. It must be inside the tunnel, otherwise site names go to your ISP.
  • PublicKey: the server's key, used to verify you're talking to the right server.
  • Endpoint: the server's address and port.
  • AllowedIPs: which destinations go through the tunnel; 0.0.0.0/0, ::/0 means everything, IPv4 and IPv6; a subnet calculator turns a range like 192.168.1.0/24 into its addresses.
  • PersistentKeepalive: a small packet every 25 seconds so your carrier's NAT (address swapping at the edge of a network) doesn't forget the connection exists.

Your provider gives you this file or a QR code ready to use; you don't need to edit it.

ONE FILE, TWO SECTIONSFIG. 01
[Interface]  about you
  PrivateKey your key, never shared
  Address    your tunnel address
  DNS        who resolves names
[Peer]       about the server
  AllowedIPs what routes through it
The two bracketed sections split your identity from the server's, which is why switching servers never means regenerating your own key.

How to set up WireGuard on Windows

  1. Download the client from wireguard.com.
  2. Import Tunnel and select the .conf file, or Add Empty Tunnel and paste the configuration.
  3. Activate. If "Latest handshake" shows a time, you're up.
  4. Confirm at What Is My IP.

Two gotchas. The client turns on "Block untunneled traffic" by default, so your internet dies when the tunnel drops. That's correct behavior, not a bug, and you want it on. And if the server doesn't support IPv6 but the config includes ::/0, IPv6-only sites won't open; remove ::/0.

ONE CONFIG, MANY DEVICESFIG. 02
never reuse a key across devices
  └─ you cannot revoke one of them
generate a pair per device
   └─ the server lists each as its
      own peer

How to set up WireGuard on Mac

Install from the App Store or wireguard.com, then Import Tunnel from File or paste the configuration. Activate from the menu bar icon. Check the address the same way.

THE SAME FILE EVERYWHEREFIG. 03
Windows   official app
macOS     official app
iPhone    official app
Android   official app
router    package in firmware
   └─ one config, five places

WireGuard on iPhone and iPad

  1. Install the WireGuard app from the App Store, or your provider's app with WireGuard built in.
  2. Tap +, then Create from QR code and scan, or Create from file.
  3. Allow the VPN configuration when iOS asks.
  4. Optionally enable On-Demand Activation in the tunnel's settings so it connects automatically on Wi-Fi or on specific networks.

WireGuard on Android

  1. Install WireGuard from Google Play.
  2. +, then scan the QR code or import the file.
  3. Allow the connection request.
  4. In system settings, enable Always-on VPN and Block connections without VPN for the WireGuard app, and set its battery usage to Unrestricted. Why those matter is in how to set up a VPN on Android.
  5. If the connection drops on mobile data, confirm PersistentKeepalive = 25 is in the config.
WHAT AllowedIPs ACTUALLY DOESFIG. 04
0.0.0.0/0    route everything inside
10.0.0.0/24  route only that subnet
   └─ this single line decides
      whether it is a full VPN or
      just a link to one network

WireGuard on an OpenWrt router

This is the route for TVs and consoles that can't run an app of their own.

ON THE ROUTER: ONE TUNNEL FOR THE WHOLE HOUSETVConsoleLaptopOpenWrt routerWireGuard interfaceencrypted tunnelVPN serverresolver in the tunnelupstream DNS outside the tunnelISP resolverevery device's namesPoint the router's upstream DNS inside the tunnel. Its CPU sets the speed ceiling.
Set it up once on the router and the whole house shares the tunnel, as long as DNS goes through it too.
  1. opkg update && opkg install wireguard-tools luci-proto-wireguard.
  2. Network → Interfaces → Add new, protocol WireGuard VPN, enter the private key and Address.
  3. On the Peers tab add the server's public key, Endpoint, AllowedIPs and keepalive; check Route Allowed IPs.
  4. Firewall: put the new interface in the wan zone (or its own), allow lan → that zone, enable masquerading.
  5. DNS: in DHCP/DNS settings, point the upstream resolver at the address inside the tunnel, or every device in your house leaks its DNS (the internet's phone book) queries.
  6. Restart the network and confirm from a device on the LAN at What Is My IP.

Your router's CPU sets the ceiling: entry-level hardware gives you tens to a couple of hundred megabits, and gigabit wants x86 or a fast ARM board. The wider trade-offs are in VPN on router vs on each device.

WHEN WIREGUARD IS THE WRONG PICKFIG. 05
the network drops UDP entirely
the network classifies protocols
you need to look like plain HTTPS
   └─ in those three cases no amount
      of tuning helps

Budget about five minutes for the whole thing, and quite a bit longer on a router: how long a VPN takes to set up breaks the time down step by step.

When to use VLESS instead

WireGuard runs over UDP with a recognizable pattern. On networks that block UDP or throttle VPNs (offices, campuses, some hotels, some countries) it fails where VLESS with Reality, which looks like ordinary HTTPS, keeps working. On normal home and mobile networks WireGuard is faster and lighter. An app that switches automatically spares you the decision.

FOUR SYMPTOMS, FOUR CAUSESFIG. 06
no handshake            key or endpoint
handshake, no data      AllowedIPs
IP works, names don't   DNS
breaks on mobile        MTU
Match the exact symptom and skip straight to the one setting worth checking, instead of guessing through all of them.

If you have a config but the lines mean nothing to you, walk through it with an AI. Leave the keys out.

Prompt for an AI
Explain my WireGuard config line by line.

Here it is with the keys removed:

[Interface]
Address = (yours)
DNS = (yours)
MTU = (if present)

[Peer]
AllowedIPs = (yours)
Endpoint = (city, or "hidden")
PersistentKeepalive = (if present)

Say what each line does, whether all traffic will
go through the tunnel with this AllowedIPs, and
what to change if it breaks on mobile data.
Do not invent lines my config does not have.

Never paste PrivateKey or PublicKey anywhere: the private key is your entire access.

WireGuard not connecting: troubleshooting

  • No handshake: wrong address or port, wrong public key, or your device's clock has drifted. Turn on automatic time.
  • Handshake but nothing loads: AllowedIPs doesn't cover where you're going, your DNS is outside the tunnel, or your IPv6 doesn't match the server's.
  • Drops after a few minutes on a phone: no keepalive, or your system froze the app in the background.
  • Only a few megabits: the server is far away, or your router's CPU is maxed out.
  • Works on mobile data, dead on Wi-Fi: that network blocks UDP, so use VLESS there. Causes in VPN not working on Wi-Fi.

404 VPN now gives WireGuard configs for Istanbul and Marseille: on the Keys page of the dashboard, switch to WireGuard, then import the .conf file or scan the QR code; DNS stays inside the tunnel. A router that supports WireGuard can use such a file too. VLESS with Reality runs in the 404 VPN apps, with a kill switch on Android. You choose the protocol yourself, and for WireGuard, blocking traffic when the tunnel drops is a setting of the WireGuard app or your phone. How the connection works is on the how it works page; get started here.