WireGuard

WireGuard

Free, open-source VPN protocol and tools for fast, simple remote access to office or home networks. Tunnels are defined by short key-based config files. Official apps for Windows, macOS, iOS and Android; built into the Linux kernel since 5.6.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp
FreeLatest version: 1.1.1Actively developed

WireGuard is a modern, minimal VPN protocol and toolset for admins who want fast, low-maintenance remote access to office, lab or home networks from Windows, macOS, Linux, iOS and Android. The WireGuard download is free: the Linux kernel code and the wg tools are GPL-2.0, the Windows client is MIT-licensed, and there is no paid edition.

A WireGuard tunnel is defined by a short text file: a private key, an address and a list of peers with their public keys and allowed IP ranges. There are no certificates, no user database and no cipher negotiation, which is why setups that take an afternoon with other VPNs often take ten minutes here. WireGuard has been part of the mainline Linux kernel since 5.6, and the Windows client reached 1.0 in April 2026.

WireGuard at a glance

Item Details
Latest version WireGuard for Windows 1.1.1 (20 September 2026); wireguard-tools 1.0.20260223 (23 February 2026); on Linux the protocol is part of the kernel
Licence Free and open source: GPL-2.0 (Linux kernel module, wireguard-tools), MIT (Windows client)
Platforms Windows 10/11 (x64, ARM64, x86), Linux, macOS, iOS, Android, FreeBSD, OpenBSD
Developer Jason A. Donenfeld / WireGuard LLC
Official website wireguard.com
Best for Fast point-to-site access for admins, site-to-site links, always-on tunnels to labs and home networks

What it does

  • Creates an encrypted layer-3 tunnel over UDP between peers identified only by Curve25519 public keys.
  • Routes by “cryptokey routing”: each peer’s AllowedIPs list decides which addresses go to it and which source addresses it may use.
  • Uses a fixed modern cipher suite (ChaCha20-Poly1305, Curve25519, BLAKE2s), so there is nothing to negotiate or misconfigure.
  • Roams cleanly: a laptop that changes from Wi-Fi to LTE keeps its tunnel, and the server learns the new endpoint from authenticated packets.
  • Stays silent to unauthenticated packets, so a port scan does not reveal that a WireGuard server is listening.
  • Keeps NAT mappings open with PersistentKeepalive for peers behind home routers.
  • On Windows, runs each tunnel as a service, can block all untunnelled traffic when the tunnel routes 0.0.0.0/0, and installs from MSI packages for Group Policy or Intune.

How IT teams use it

Reach the office LAN from a laptop

  1. On the Linux server, generate keys: umask 077; wg genkey | tee server.key | wg pubkey > server.pub. Do the same for the laptop (or let the Windows or Mac app generate them).
  2. Create /etc/wireguard/wg0.conf on the server and start it with systemctl enable --now wg-quick@wg0.
  3. Enable forwarding (sysctl -w net.ipv4.ip_forward=1) and either add a route on the LAN router to 10.20.0.0/24 via the server, or NAT the VPN subnet on the server.
  4. Open UDP 51820 on the edge firewall and import the client config on the laptop.
# server: /etc/wireguard/wg0.conf
[Interface]
Address = 10.20.0.1/24
ListenPort = 51820
PrivateKey = <server private key>

[Peer]
# alice-laptop
PublicKey = <laptop public key>
AllowedIPs = 10.20.0.2/32

# client
[Interface]
PrivateKey = <laptop private key>
Address = 10.20.0.2/32
DNS = 192.168.10.10

[Peer]
PublicKey = <server public key>
Endpoint = vpn.example.com:51820
AllowedIPs = 10.20.0.0/24, 192.168.10.0/24
PersistentKeepalive = 25

Only the two internal ranges go through the tunnel, so the technician can open RDP, SSH or VNC to 192.168.10.x while normal web traffic stays local.

Add or remove a user without a restart

  1. Add the peer live: wg set wg0 peer <public key> allowed-ips 10.20.0.3/32.
  2. Persist the change with wg-quick save wg0, or add the [Peer] block to the file.
  3. To revoke access, run wg set wg0 peer <public key> remove and delete the block. Check who is connected with wg show (look at “latest handshake”).

Deploy an always-on tunnel to Windows machines

  1. Push the MSI with your deployment tool; the DO_NOT_LAUNCH=1 property stops the UI from opening after install.
  2. Copy the tunnel file to a protected folder and install it as a service: wireguard /installtunnelservice C:ProgramDatavpnoffice.conf.
  3. Remove it later with wireguard /uninstalltunnelservice office.

Install and first run

Windows. WireGuard for Windows supports Windows 10 (build 1507 and later) and Windows 11, on x64, ARM64 and x86. Installing and managing tunnels requires local admin rights; by default the tray UI appears only for Administrators, with an optional limited UI for the Network Configuration Operators group set by registry. The client updates itself.

Linux. Kernels 5.6 and newer include WireGuard; install the wireguard-tools package for wg and wg-quick. Configs live in /etc/wireguard/ and should be readable by root only.

macOS, iOS, Android. Install the official WireGuard app from the App Store or Google Play and import a config file or scan a QR code (qrencode -t ansiutf8 < alice.conf prints one in a terminal). On macOS, wireguard-tools from Homebrew adds the command-line tools.

Gotchas. WireGuard has no fixed port; 51820/UDP is the common convention and must be forwarded to the server. If a tunnel shows as active but nothing passes, check that “latest handshake” updates in wg show; if it never does, the keys, endpoint or firewall are wrong. Overlapping AllowedIPs between two peers silently steals traffic from one of them.

Limitations

  • UDP only. Networks that allow nothing but TCP 443 will block it unless you add an external wrapper.
  • No user accounts, passwords or MFA: whoever holds a private key is in. Key distribution and revocation are manual.
  • No built-in address pool (DHCP); you assign a tunnel IP to every peer yourself.
  • The server keeps each peer’s last endpoint IP in memory, which some privacy-focused setups need to handle.
  • No central management console in the project itself; larger fleets usually add a management layer or a commercial service built on WireGuard.

WireGuard vs alternatives

OpenVPN is slower to set up but works over TCP, supports certificate revocation and can check usernames and passwords against LDAP or RADIUS, which suits larger user bases. Tailscale and similar mesh services use WireGuard underneath and add identity sign-in, NAT traversal and an admin console, at the cost of depending on a third-party coordination service. Plain WireGuard is the right choice when you control the server and want the simplest, fastest tunnel.

FAQ

Is WireGuard free?

Yes. WireGuard is free and open source on every platform; the kernel code and tools are GPL-2.0 and the Windows client is MIT.

What port does WireGuard use?

Whatever you set in ListenPort. UDP 51820 is the convention used in the official examples; there is no TCP mode.

WireGuard vs OpenVPN: which is faster?

WireGuard is usually faster and uses less CPU because of its small code base and in-kernel implementation. OpenVPN with kernel offload (DCO) narrows the gap.

WireGuard vs Tailscale: what is the difference?

Tailscale is a service built on the WireGuard protocol that handles key exchange, sign-in and NAT traversal for you. Plain WireGuard means you manage keys and endpoints yourself, with no external dependency.

Is there a WireGuard client for Mac?

Yes, the official WireGuard app is in the Mac App Store, and the command-line tools are available through Homebrew.

How do I set up a WireGuard tunnel on Windows?

Install the client, choose Add Tunnel to import a .conf file (or create an empty tunnel to generate keys), then click Activate. Admin rights are required.

Does WireGuard work behind NAT?

Yes, as long as one side has a reachable UDP port. Set PersistentKeepalive = 25 on peers behind NAT to keep the mapping open.

Last checked against official sources: 1 October 2026 (developer website: wireguard.com). Versions and licence terms change — confirm on the developer's site before deploying in production.

Other programs

Submit your application