服务端安装:
apt update && apt install wireguard -y
cd /etc/wireguard && umask 077
wg genkey | tee server_private.key | wg pubkey > server_public.key
服务端配置 /etc/wireguard/wg0.conf:
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = (服务端私钥)
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = (客户端公钥)
AllowedIPs = 10.8.0.2/32
客户端配置:
[Interface]
PrivateKey = (客户端私钥)
Address = 10.8.0.2/24
DNS = 1.1.1.1
[Peer]
PublicKey = (服务端公钥)
Endpoint = VPS-IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25