WireGuard is a few hundred lines of kernel code and two small config files, and the whole setup takes about fifteen minutes once you know which port to open. The part that actually trips people up on a budget VPS is not WireGuard at all — it is that the port you tell WireGuard to listen on has to be one the provider already forwards to you.WireGuard ist ein paar hundert Zeilen Kernel-Code und zwei kleine Konfigurationsdateien, und das komplette Setup dauert etwa fünfzehn Minuten, sobald du weißt, welchen Port du öffnen musst. Was Leute bei einem günstigen VPS tatsächlich stolpern lässt, ist gar nicht WireGuard selbst — sondern dass der Port, auf den du WireGuard hören lässt, einer sein muss, den der Provider bereits zu dir weiterleitet.
WireGuard is not a service you install and forget about; it is a network interface. The kernel module has shipped in mainline Linux since version 5.6, so on Ubuntu 24.04 it is already part of the kernel you booted — there is no dkms build, no compiling against headers, nothing to break on a kernel update. What you install is wireguard-tools, which gives you two commands: wg, for keys and status, and wg-quick, which reads a config file and brings the interface up or down as a single unit.WireGuard ist kein Dienst, den du installierst und dann vergisst; es ist eine Netzwerkschnittstelle. Das Kernel-Modul ist seit Version 5.6 Teil des Mainline-Linux, auf Ubuntu 24.04 also bereits Teil des Kernels, den du gebootet hast — kein dkms-Build, kein Kompilieren gegen Header, nichts, was bei einem Kernel-Update kaputtgehen kann. Was du installierst, ist wireguard-tools, das dir zwei Befehle gibt: wg für Keys und Status, und wg-quick, das eine Konfigurationsdatei liest und die Schnittstelle als eine Einheit hoch- oder herunterfährt.
That simplicity is also the constraint. There is no built-in dashboard, no user accounts, and no bandwidth graph. Every peer, on either end, is one public key and one line of config. Getting comfortable editing a text file by hand is the whole job.Diese Einfachheit ist zugleich die Grenze. Es gibt kein eingebautes Dashboard, keine Benutzerkonten und keinen Bandbreiten-Graphen. Jeder Peer ist auf beiden Seiten ein Public Key und eine Zeile Konfiguration. Sich daran zu gewöhnen, eine Textdatei von Hand zu bearbeiten, ist der ganze Job.
Cheap VPS plans very commonly give you NAT IPv4 — one shared public address with a small, fixed set of forwarded ports — rather than an address that is yours alone. That is fine for outbound connections, which is all a WireGuard client ever makes. It matters the moment your VPS is the WireGuard server, because a server has to accept an inbound connection on a specific UDP port, and behind NAT you cannot just pick 51820 because a guide told you to.Günstige VPS-Tarife geben dir sehr häufig NAT-IPv4 — eine geteilte öffentliche Adresse mit einer kleinen, festen Menge weitergeleiteter Ports — statt einer Adresse, die dir allein gehört. Das ist für ausgehende Verbindungen kein Problem, und mehr macht ein WireGuard-Client nie. Es wird relevant, sobald dein VPS der WireGuard-Server ist, denn ein Server muss eine eingehende Verbindung auf einem bestimmten UDP-Port annehmen, und hinter NAT kannst du nicht einfach 51820 wählen, nur weil eine Anleitung das gesagt hat.
The rule is simple once you know it: ListenPort in your server config must be set to one of the ports your provider actually forwards to your machine, and the client's Endpoint must use that same port. Pick a random port instead and the tunnel will look correctly configured on both ends and simply never connect, because the packets never reach your VPS in the first place.Die Regel ist einfach, sobald du sie kennst: ListenPort in deiner Server-Konfiguration muss auf einen der Ports gesetzt sein, die dein Provider tatsächlich zu deiner Maschine weiterleitet, und der Endpoint des Clients muss denselben Port verwenden. Wählst du stattdessen einen zufälligen Port, sieht der Tunnel auf beiden Seiten korrekt konfiguriert aus und verbindet sich einfach nie, weil die Pakete deinen VPS von vornherein nie erreichen.
Two ways through it:Zwei Wege, das zu lösen:
ListenPort at whichever forwarded port is free and move on.Nutze einen der weitergeleiteten Ports, die du schon hast. WireGuard ist es egal, auf welcher Nummer es läuft, also richte ListenPort auf einen freien weitergeleiteten Port und mach weiter.Read NAT IPv4 vs a dedicated IP and NAT IPv4, ports and forwarding before you order if you are not sure which situation you are in.Lies NAT IPv4 vs. dedizierte IP und NAT IPv4, Ports und Weiterleitung, bevor du bestellst, falls du nicht sicher bist, in welcher Situation du dich befindest.
Deploy an Ubuntu 24.04 LTS VPS, then do the boring security work before anything is exposed to the internet: a non-root user, your SSH key on it, password login switched off, and a firewall that defaults to deny. We walk through that in connect to your VPS over SSH and secure your VPS.Setze einen Ubuntu-24.04-LTS-VPS auf, und erledige dann die langweilige Sicherheitsarbeit, bevor irgendetwas dem Internet ausgesetzt ist: einen Non-Root-User, deinen SSH-Key darauf, Passwort-Login deaktiviert, und eine Firewall, die standardmäßig blockiert. Das zeigen wir in über SSH mit deinem VPS verbinden und deinen VPS absichern.
Note the forwarded UDP port range or list from your provider's panel before you go further — you need an actual number for the next step, not a placeholder.Notiere dir den weitergeleiteten UDP-Portbereich oder die Portliste aus dem Panel deines Providers, bevor du weitermachst — du brauchst für den nächsten Schritt eine echte Zahl, keinen Platzhalter.
sudo apt update
sudo apt install -y wireguard
That pulls in wireguard-tools; the kernel side is already present. Installing it also creates /etc/wireguard owned by root with mode 0700, so your regular sudo user cannot cd into it or write a key there — generate the server's key pair as root, with a strict umask so the private key is never briefly world-readable:Das zieht wireguard-tools mit; die Kernel-Seite ist schon vorhanden. Die Installation legt außerdem /etc/wireguard an, das root gehört, mit dem Modus 0700, sodass dein normaler Sudo-User weder mit cd hineinwechseln noch dort einen Key schreiben kann — erzeuge das Schlüsselpaar des Servers als root, mit einer strikten Umask, damit der Private Key nie kurzzeitig für alle lesbar ist:
sudo -i
cd /etc/wireguard
umask 077
wg genkey | tee server_private.key | wg pubkey > server_public.key
exit
Do the whole block in one root shell rather than prefixing each line with sudo — sudo does not inherit the umask 077 you just set, so a command like sudo tee can still create the key file with its own default, more permissive mode even though the umask line ran.Führe den ganzen Block in einer einzigen Root-Shell aus, statt jeder Zeile ein sudo voranzustellen — sudo erbt die gerade gesetzte umask 077 nicht, sodass ein Befehl wie sudo tee die Key-Datei trotzdem mit seinem eigenen, permissiveren Standardmodus anlegen kann, obwohl die Umask-Zeile gelaufen ist.
Generate a second pair for the client the same way, on whichever machine will hold it — it does not have to be the server. Keep the two private keys apart; only the matching public key ever leaves its own side.Erzeuge auf dieselbe Weise ein zweites Paar für den Client, auf welcher Maschine auch immer es liegen soll — das muss nicht der Server sein. Halte die beiden Private Keys getrennt; nur der jeweils passende Public Key verlässt jemals seine eigene Seite.
Create /etc/wireguard/wg0.conf, using one of your forwarded ports for ListenPort:Erstelle /etc/wireguard/wg0.conf und verwende für ListenPort einen deiner weitergeleiteten Ports:
[Interface]
PrivateKey = <server_private.key contents>
Address = 10.66.66.1/24
ListenPort = 41194
PostUp = iptables -t nat -A POSTROUTING -o <WAN_INTERFACE> -j MASQUERADE; iptables -A FORWARD -i wg0 -j ACCEPT
PostDown = iptables -t nat -D POSTROUTING -o <WAN_INTERFACE> -j MASQUERADE; iptables -D FORWARD -i wg0 -j ACCEPT
[Peer]
PublicKey = <client public key>
AllowedIPs = 10.66.66.2/32
Replace <WAN_INTERFACE> with your real outbound interface name, not eth0. Find it first:Ersetze <WAN_INTERFACE> durch den Namen deiner echten ausgehenden Schnittstelle, nicht durch eth0. Finde ihn zuerst heraus:
ip -brief link
This is the thing that bites later: most published examples hardcode eth0, but plenty of KVM images come up as ens3, enp1s0 or similar. Get the name wrong and the tunnel connects fine, wg show looks healthy, and the client still has no internet through it, because the MASQUERADE rule silently applies to an interface that does not exist.Das ist die Sache, die später zubeißt: Die meisten veröffentlichten Beispiele hartcodieren eth0, aber viele KVM-Images kommen als ens3, enp1s0 oder Ähnliches hoch. Nimmst du den falschen Namen, verbindet sich der Tunnel trotzdem problemlos, wg show sieht gesund aus, und der Client hat trotzdem kein Internet darüber, weil die MASQUERADE-Regel still auf eine Schnittstelle angewendet wird, die es gar nicht gibt.
Turn on IP forwarding and make it survive a reboot:Schalte IP-Forwarding ein und sorge dafür, dass es einen Neustart übersteht:
echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/99-wireguard.conf
sudo sysctl --system
Open the same forwarded port, over UDP, and nothing else new:Öffne denselben weitergeleiteten Port, über UDP, und sonst nichts Neues:
sudo ufw allow 41194/udp
WireGuard is UDP end to end. A rule that opens the port as TCP by mistake produces the same symptom as picking a non-forwarded port: everything looks configured and nothing arrives. If you change the listen port later, update it in three places at once — the config file, the firewall rule, and every client's Endpoint — or you will spend ten minutes debugging a mismatch you made yourself five minutes earlier.WireGuard ist von Anfang bis Ende UDP. Eine Regel, die den Port versehentlich als TCP öffnet, erzeugt dasselbe Symptom wie ein nicht weitergeleiteter Port: Alles sieht konfiguriert aus, und nichts kommt an. Änderst du den Listen-Port später, aktualisiere ihn an drei Stellen gleichzeitig — die Konfigurationsdatei, die Firewall-Regel und den Endpoint jedes Clients — sonst verbringst du zehn Minuten damit, eine Unstimmigkeit zu debuggen, die du dir selbst fünf Minuten vorher eingebrockt hast.
If you followed Step 1's advice and have ufw running, there is a second gate to check: ufw ships with DEFAULT_FORWARD_POLICY="DROP" in /etc/default/ufw, which blocks exactly the routed, NAT'd traffic this tunnel exists to move, regardless of the port being open. Edit that file, set DEFAULT_FORWARD_POLICY="ACCEPT", and run sudo ufw reload before you test a client — leave it on DROP and the handshake still completes and wg show still looks healthy, but the client has no internet through the tunnel.Bist du Schritt 1 gefolgt und hast ufw laufen, gibt es ein zweites Tor zu prüfen: ufw liefert DEFAULT_FORWARD_POLICY="DROP" in /etc/default/ufw, was genau den gerouteten, genatteten Traffic blockiert, den dieser Tunnel bewegen soll — unabhängig davon, ob der Port offen ist. Bearbeite diese Datei, setze DEFAULT_FORWARD_POLICY="ACCEPT", und führe sudo ufw reload aus, bevor du einen Client testest — lässt du es auf DROP, schließt der Handshake trotzdem ab und wg show sieht weiterhin gesund aus, aber der Client hat kein Internet über den Tunnel.
This is the entire client side, for the official WireGuard app on any platform or for wg-quick on another Linux box:Das ist die komplette Client-Seite, für die offizielle WireGuard-App auf jeder Plattform oder für wg-quick auf einer anderen Linux-Maschine:
[Interface]
PrivateKey = <client private key>
Address = 10.66.66.2/32
DNS = 1.1.1.1
[Peer]
PublicKey = <server_public.key contents>
Endpoint = 203.0.113.10:41194
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25
Replace 203.0.113.10 with your VPS's public NAT IPv4 address and 41194 with the forwarded port from Step 3. AllowedIPs = 0.0.0.0/0 routes all of the client's traffic through the tunnel, which is what most people mean by "my own VPN" — narrow it to specific subnets if you only want the tunnel for part of your traffic. PersistentKeepalive = 25 matters specifically because the client usually sits behind its own NAT (a home router, a phone on mobile data); without it, that NAT's connection tracking entry expires during idle periods and the server cannot reach the client until it sends something first.Ersetze 203.0.113.10 durch die öffentliche NAT-IPv4-Adresse deines VPS und 41194 durch den weitergeleiteten Port aus Schritt 3. AllowedIPs = 0.0.0.0/0 leitet den gesamten Traffic des Clients durch den Tunnel, was die meisten Leute meinen, wenn sie „mein eigenes VPN“ sagen — schränke es auf bestimmte Subnetze ein, wenn du den Tunnel nur für einen Teil deines Traffics willst. PersistentKeepalive = 25 ist speziell deshalb wichtig, weil der Client meist hinter seinem eigenen NAT sitzt (ein Heimrouter, ein Smartphone im Mobilfunknetz); ohne das läuft der Connection-Tracking-Eintrag dieses NATs während Leerlaufphasen ab, und der Server kann den Client nicht mehr erreichen, bis dieser zuerst etwas sendet.
Bring the interface up and enable it for every future boot in one command:Bring die Schnittstelle mit einem einzigen Befehl hoch und aktiviere sie für jeden zukünftigen Boot:
sudo systemctl enable --now wg-quick@wg0
Check it with sudo wg show, which lists the peer, the last handshake time and the bytes moved in each direction — a peer with no handshake ever recorded means the packets are not arriving, which sends you back to Step 3's interface name or Step 4's port. sudo systemctl status wg-quick@wg0 and journalctl -u wg-quick@wg0 cover the rest.Prüfe es mit sudo wg show, das den Peer, den Zeitpunkt des letzten Handshakes und die in jede Richtung bewegten Bytes anzeigt — ein Peer, für den nie ein Handshake verzeichnet ist, bedeutet, dass die Pakete nicht ankommen, was dich zurück zum Schnittstellennamen aus Schritt 3 oder zum Port aus Schritt 4 schickt. sudo systemctl status wg-quick@wg0 und journalctl -u wg-quick@wg0 decken den Rest ab.
There is no key rotation schedule to maintain and no update service running that needs restarting on a cadence — WireGuard's attack surface is deliberately small. The two things actually worth a recurring check: that wireguard-tools picks up routine security updates with the rest of the system (sudo apt update && sudo apt upgrade), and that nothing in your provider's panel changes which ports are forwarded to you, since that is the one setting this whole guide hangs off.Es gibt keinen Key-Rotations-Zeitplan zu pflegen und keinen laufenden Update-Dienst, der in regelmäßigem Takt neu gestartet werden muss — die Angriffsfläche von WireGuard ist bewusst klein. Die zwei Dinge, die wirklich eine wiederkehrende Prüfung wert sind: dass wireguard-tools mit dem Rest des Systems die üblichen Sicherheitsupdates mitnimmt (sudo apt update && sudo apt upgrade), und dass sich im Panel deines Providers nichts daran ändert, welche Ports zu dir weitergeleitet werden, denn genau daran hängt diese gesamte Anleitung.
Our machines run in Dallas, TX and Charlotte, NC, so a WireGuard server there gives you a US exit address — sites you visit see that VPS's IP, not your home or mobile connection's. Inside the tunnel, your local network operator, your ISP and anyone else between you and the VPS sees only encrypted WireGuard packets to one UDP port; they cannot read what is inside them or which sites you are actually visiting.Unsere Maschinen laufen in Dallas, TX und Charlotte, NC; ein WireGuard-Server dort gibt dir also eine US-Austrittsadresse — Seiten, die du besuchst, sehen die IP dieses VPS, nicht die deiner Heim- oder Mobilfunkverbindung. Innerhalb des Tunnels sehen dein lokaler Netzbetreiber, dein ISP und jeder andere zwischen dir und dem VPS nur verschlüsselte WireGuard-Pakete zu einem UDP-Port; sie können weder lesen, was darin steckt, noch welche Seiten du tatsächlich besuchst.
What it does not do is anonymise you. Any site you log into still recognises you as you, regardless of which IP address you arrive from. Browser fingerprinting is unaffected — cookies, canvas fingerprinting and account sessions do not care what your network path looks like. Your traffic's final destination is also visible to the operator of that VPS, because unlike a multi-hop system such as Tor, this is a single hop: your ISP no longer sees your browsing, but something has to terminate the tunnel and see the traffic in cleartext before it goes onward, and that something is your own VPS. Geolocation-wise, expect exactly one change: sites that check IP location will place you in Texas or North Carolina, and a few services that treat datacentre address ranges differently from residential ones may notice that too.Was es nicht tut, ist dich zu anonymisieren. Jede Seite, bei der du dich einloggst, erkennt dich weiterhin als dich, egal von welcher IP-Adresse du kommst. Browser-Fingerprinting bleibt unberührt — Cookies, Canvas-Fingerprinting und Account-Sessions interessiert es nicht, wie dein Netzwerkpfad aussieht. Das endgültige Ziel deines Traffics ist zudem für den Betreiber dieses VPS sichtbar, denn anders als bei einem Multi-Hop-System wie Tor ist das hier nur ein einziger Hop: Dein ISP sieht dein Surfverhalten nicht mehr, aber irgendetwas muss den Tunnel terminieren und den Traffic im Klartext sehen, bevor er weitergeht, und dieses Etwas ist dein eigener VPS. Geolokalisierungstechnisch erwartet dich genau eine Änderung: Seiten, die den IP-Standort prüfen, verorten dich in Texas oder North Carolina, und ein paar Dienste, die Rechenzentrums-Adressbereiche anders behandeln als private, bemerken das eventuell ebenfalls.
Full disclosure: this is what we sell. A 1 vCPU, 1 GiB Starter runs a personal WireGuard tunnel without noticing it; move up a tier only once you are pushing serious throughput or running several always-on tunnels off the same box.Zur vollen Transparenz: Das ist, was wir verkaufen. Ein 1-vCPU-1-GiB-Starter betreibt einen persönlichen WireGuard-Tunnel, ohne es zu merken; steige erst eine Stufe höher, sobald du ernsthaften Durchsatz fährst oder mehrere dauerhaft aktive Tunnel von derselben Maschine aus betreibst.
Linux KVM VPS — EUR 4.99 to EUR 59.99 a month, on our own single-tenant bare metal in Dallas, TX and Charlotte, NC. Full hardware virtualisation (KVM), your own kernel, full root. Six tiers, vps-starter to vps-ultra. Starter is 1 vCPU, 1 GiB RAM, 25 GB disk.Linux-KVM-VPS — 4,99 bis 59,99 EUR im Monat, auf unserer eigenen Single-Tenant-Bare-Metal-Hardware in Dallas, TX und Charlotte, NC. Vollständige Hardware-Virtualisierung (KVM), eigener Kernel, volles Root. Sechs Tarife, vps-starter bis vps-ultra. Starter hat 1 vCPU, 1 GiB RAM, 25 GB Speicher.
You order in the shop, pay by card (Stripe) or SEPA bank transfer, and your login details are e-mailed to you once the service is set up. Support is e-mail, run by one person, with no guaranteed response time. All prices are final totals under the German small-business rule (§19 UStG); no VAT is added or shown.Du bestellst im Shop, zahlst per Karte (Stripe) oder SEPA-Überweisung, und deine Zugangsdaten werden dir per E-Mail zugeschickt, sobald der Dienst eingerichtet ist. Support läuft per E-Mail, von einer einzelnen Person betrieben, ohne garantierte Reaktionszeit. Alle Preise sind Endpreise. Gemäß § 19 UStG wird keine Umsatzsteuer ausgewiesen.
Order vps-starter → · Linux KVM VPS overviewvps-starter bestellen → · Übersicht Linux-KVM-VPS
Written by the person who runs overnight.host: a small, honest hosting company on dedicated bare metal — Linux VPS, game servers, web hosting. Live status at up.overnight.host.Geschrieben von der Person, die overnight.host betreibt: ein kleines, ehrliches Hosting-Unternehmen auf dedizierter Bare-Metal-Hardware — Linux-VPS, Gameserver, Webhosting. Live-Status unter up.overnight.host.
No. NAT IPv4 works fine as a WireGuard server as long as ListenPort in your config is one of the ports your provider forwards to you, and every client's Endpoint uses that same port. A dedicated IPv4 only becomes useful if you want to run more services than you have forwarded ports for, or want the default port specifically.Nein. NAT-IPv4 funktioniert als WireGuard-Server problemlos, solange ListenPort in deiner Konfiguration einer der Ports ist, die dein Provider zu dir weiterleitet, und jeder Client-Endpoint denselben Port verwendet. Eine dedizierte IPv4 wird erst nützlich, wenn du mehr Dienste betreiben willst, als du weitergeleitete Ports hast, oder du speziell den Standardport willst.
The two most common causes are a ListenPort that is not actually forwarded to your VPS, and a firewall rule opened as TCP instead of UDP. Check sudo wg show for a peer with no recorded handshake — that confirms packets are not arriving at all, which points at the port rather than at routing or keys.Die zwei häufigsten Ursachen sind ein ListenPort, der nicht tatsächlich zu deinem VPS weitergeleitet wird, und eine Firewall-Regel, die versehentlich als TCP statt UDP geöffnet wurde. Prüfe mit sudo wg show, ob für einen Peer kein Handshake verzeichnet ist — das bestätigt, dass überhaupt keine Pakete ankommen, was auf den Port hindeutet und nicht auf Routing oder Keys.
Yes. Add one [Peer] block per client to the server config, each with its own public key and its own /32 address inside your chosen subnet, then reload with sudo wg syncconf wg0 <(wg-quick strip wg0) or a restart of the service. Every client keeps its own private key; only public keys go on the server.Ja. Füge der Server-Konfiguration pro Client einen [Peer]-Block hinzu, jeweils mit eigenem Public Key und eigener /32-Adresse innerhalb deines gewählten Subnetzes, und lade dann mit sudo wg syncconf wg0 <(wg-quick strip wg0) neu, oder starte den Dienst neu. Jeder Client behält seinen eigenen Private Key; auf den Server kommen nur Public Keys.
No. The VPS is where your tunnel ends and your traffic goes back onto the open internet in cleartext, so whoever controls that machine could, in principle, see it — the same is true of any VPS you use for anything. What the tunnel does hide is your traffic from your local network and your ISP between your device and that VPS.Nein. Der VPS ist der Punkt, an dem dein Tunnel endet und dein Traffic im Klartext zurück ins offene Internet geht; wer auch immer diese Maschine kontrolliert, könnte ihn also im Prinzip sehen — das gilt für jeden VPS, den du für irgendetwas nutzt, genauso. Was der Tunnel tatsächlich verbirgt, ist dein Traffic vor deinem lokalen Netzwerk und deinem ISP zwischen deinem Gerät und diesem VPS.
Nothing beyond the VPS itself. It is a kernel feature and a command-line tool, both free, with no license and no per-peer fee. A personal tunnel for one or two people idles well inside a 1 GiB Starter; sizing up only matters once you are pushing meaningful throughput through it continuously.Nichts über den VPS selbst hinaus. Es ist eine Kernel-Funktion und ein Kommandozeilen-Tool, beide kostenlos, ohne Lizenz und ohne Gebühr pro Peer. Ein persönlicher Tunnel für ein oder zwei Personen läuft im Leerlauf bequem innerhalb eines 1-GiB-Starters; Hochskalieren wird erst relevant, sobald du dauerhaft nennenswerten Durchsatz hindurchschickst.
Prices are final totals; no VAT is shown (§19 UStG). Need something the shop does not list? Email us for a written offer.Alle Preise sind Endpreise ohne ausgewiesene USt. (§19 UStG). Du brauchst etwas, das nicht im Shop steht? Schreib uns für ein schriftliches Angebot.
Order now →Jetzt bestellen → Request a custom configIndividuelle Konfiguration anfragen