Setting up WireGuard takes a few minutes on any platform because the whole configuration is about ten lines, and on a phone it's a QR code.
The official apps exist for Windows, macOS, iOS, Android and Linux, and most routers that can run a VPN client support it. This guide explains what each line means, walks through every platform, and ends with the handful of things that go wrong. If you want to know how WireGuard compares to other protocols first, that is in WireGuard vs OpenVPN.
WireGuard config file, line by line
[Interface]
PrivateKey = your device's private key
Address = 10.0.0.2/32
DNS = 10.0.0.1
[Peer]
PublicKey = the server's public key
Endpoint = server address:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
PrivateKey: your key, never leaves the device; leaking it equals leaking the account.Address: your device's address inside the tunnel.DNS: the resolver used once the tunnel is up. It must be inside the tunnel, otherwise site names go to your ISP.PublicKey: the server's key, used to verify you're talking to the right server.Endpoint: the server's address and port.AllowedIPs: which destinations go through the tunnel;0.0.0.0/0, ::/0means everything, IPv4 and IPv6; a subnet calculator turns a range like192.168.1.0/24into its addresses.PersistentKeepalive: a small packet every 25 seconds so your carrier's NAT (address swapping at the edge of a network) doesn't forget the connection exists.
Your provider gives you this file or a QR code ready to use; you don't need to edit it.
[Interface] about you PrivateKey your key, never shared Address your tunnel address DNS who resolves names [Peer] about the server AllowedIPs what routes through it
How to set up WireGuard on Windows
- Download the client from wireguard.com.
- Import Tunnel and select the
.conffile, or Add Empty Tunnel and paste the configuration. - Activate. If "Latest handshake" shows a time, you're up.
- Confirm at What Is My IP.
Two gotchas. The client turns on "Block untunneled traffic" by default, so your internet dies when the tunnel drops. That's correct behavior, not a bug, and you want it on. And if the server doesn't support IPv6 but the config includes ::/0, IPv6-only sites won't open; remove ::/0.
never reuse a key across devices └─ you cannot revoke one of them generate a pair per device └─ the server lists each as its own peer
How to set up WireGuard on Mac
Install from the App Store or wireguard.com, then Import Tunnel from File or paste the configuration. Activate from the menu bar icon. Check the address the same way.
Windows official app macOS official app iPhone official app Android official app router package in firmware └─ one config, five places
WireGuard on iPhone and iPad
- Install the WireGuard app from the App Store, or your provider's app with WireGuard built in.
- Tap +, then Create from QR code and scan, or Create from file.
- Allow the VPN configuration when iOS asks.
- Optionally enable On-Demand Activation in the tunnel's settings so it connects automatically on Wi-Fi or on specific networks.
WireGuard on Android
- Install WireGuard from Google Play.
- +, then scan the QR code or import the file.
- Allow the connection request.
- In system settings, enable Always-on VPN and Block connections without VPN for the WireGuard app, and set its battery usage to Unrestricted. Why those matter is in how to set up a VPN on Android.
- If the connection drops on mobile data, confirm
PersistentKeepalive = 25is in the config.
0.0.0.0/0 route everything inside 10.0.0.0/24 route only that subnet └─ this single line decides whether it is a full VPN or just a link to one network
WireGuard on an OpenWrt router
This is the route for TVs and consoles that can't run an app of their own.
opkg update && opkg install wireguard-tools luci-proto-wireguard.- Network → Interfaces → Add new, protocol WireGuard VPN, enter the private key and
Address. - On the Peers tab add the server's public key, Endpoint, AllowedIPs and keepalive; check Route Allowed IPs.
- Firewall: put the new interface in the wan zone (or its own), allow lan → that zone, enable masquerading.
- DNS: in DHCP/DNS settings, point the upstream resolver at the address inside the tunnel, or every device in your house leaks its DNS (the internet's phone book) queries.
- Restart the network and confirm from a device on the LAN at What Is My IP.
Your router's CPU sets the ceiling: entry-level hardware gives you tens to a couple of hundred megabits, and gigabit wants x86 or a fast ARM board. The wider trade-offs are in VPN on router vs on each device.
the network drops UDP entirely the network classifies protocols you need to look like plain HTTPS └─ in those three cases no amount of tuning helps
Budget about five minutes for the whole thing, and quite a bit longer on a router: how long a VPN takes to set up breaks the time down step by step.
When to use VLESS instead
WireGuard runs over UDP with a recognizable pattern. On networks that block UDP or throttle VPNs (offices, campuses, some hotels, some countries) it fails where VLESS with Reality, which looks like ordinary HTTPS, keeps working. On normal home and mobile networks WireGuard is faster and lighter. An app that switches automatically spares you the decision.
no handshake key or endpoint handshake, no data AllowedIPs IP works, names don't DNS breaks on mobile MTU
If you have a config but the lines mean nothing to you, walk through it with an AI. Leave the keys out.
Explain my WireGuard config line by line.
Here it is with the keys removed:
[Interface]
Address = (yours)
DNS = (yours)
MTU = (if present)
[Peer]
AllowedIPs = (yours)
Endpoint = (city, or "hidden")
PersistentKeepalive = (if present)
Say what each line does, whether all traffic will
go through the tunnel with this AllowedIPs, and
what to change if it breaks on mobile data.
Do not invent lines my config does not have.
Never paste PrivateKey or PublicKey anywhere: the private key is your entire access.
WireGuard not connecting: troubleshooting
- No handshake: wrong address or port, wrong public key, or your device's clock has drifted. Turn on automatic time.
- Handshake but nothing loads:
AllowedIPsdoesn't cover where you're going, your DNS is outside the tunnel, or your IPv6 doesn't match the server's. - Drops after a few minutes on a phone: no keepalive, or your system froze the app in the background.
- Only a few megabits: the server is far away, or your router's CPU is maxed out.
- Works on mobile data, dead on Wi-Fi: that network blocks UDP, so use VLESS there. Causes in VPN not working on Wi-Fi.
404 VPN now gives WireGuard configs for Istanbul and Marseille: on the Keys page of the dashboard, switch to WireGuard, then import the .conf file or scan the QR code; DNS stays inside the tunnel. A router that supports WireGuard can use such a file too. VLESS with Reality runs in the 404 VPN apps, with a kill switch on Android. You choose the protocol yourself, and for WireGuard, blocking traffic when the tunnel drops is a setting of the WireGuard app or your phone. How the connection works is on the how it works page; get started here.