Raspberry Pi VPN Server with WireGuard: Complete Setup Guide

Raspberry Pi VPN Server with WireGuard: Complete Setup Guide

A Raspberry Pi can be turned into a powerful VPN server that lets you securely connect to your home network when you’re away.

With WireGuard, you can access your Raspberry Pi, NAS, Home Assistant, Jellyfin, Nextcloud, printers, and other devices as if you were connected to your home network.

WireGuard is designed as a modern VPN protocol with a relatively simple configuration. On Raspberry Pi OS, WireGuard can be installed directly through the standard package system. (WireGuard)

In this guide, we’ll build a WireGuard VPN server from scratch on a Raspberry Pi.

Important: This guide assumes that your Internet connection allows incoming connections. If your ISP uses CGNAT, traditional port forwarding may not work. In that situation, a solution such as Tailscale or a VPN server hosted on a VPS may be a better option.


What Is WireGuard?

WireGuard is a modern VPN protocol that creates an encrypted tunnel between devices.

Instead of exposing individual services on your home network, you can connect to your VPN first:

                    Internet
                       │
                       │ Encrypted VPN
                       ▼
                  ┌──────────┐
                  │ Router   │
                  └────┬─────┘
                       │
                 UDP 51820
                       │
                 ┌─────▼─────┐
                 │ Raspberry │
                 │    Pi     │
                 │ WireGuard │
                 └─────┬─────┘
                       │
                 Home Network
              ┌────────┼────────┐
              │        │        │
             NAS    Home Assistant  PC

Once connected, your remote device can access resources on your home network according to the routing configuration you choose.


Why Use a Raspberry Pi as a VPN Server?

A Raspberry Pi is well suited to this role because it can run continuously while consuming relatively little power.

Advantages

  • Low power consumption
  • Small footprint
  • Affordable
  • Always-on operation
  • Ethernet connectivity
  • Linux support
  • WireGuard support
  • Can run other home-server applications

A Raspberry Pi 4 or Raspberry Pi 5 is more than capable of handling a typical personal VPN deployment.


What Can You Access Through the VPN?

Once connected, you could access services such as:

  • SSH
  • CasaOS
  • Jellyfin
  • Nextcloud
  • Home Assistant
  • Pi-hole
  • NAS
  • Network printers
  • Windows file shares
  • Internal websites
  • Development servers
  • Other LAN devices

For example:

Laptop
   │
   │ WireGuard
   ▼
Raspberry Pi
   │
   ├── CasaOS
   ├── Jellyfin
   ├── Nextcloud
   ├── Pi-hole
   └── Home LAN

This makes WireGuard an excellent addition to a Raspberry Pi home server.


Requirements

You’ll need:

ComponentRecommendation
Raspberry PiRaspberry Pi 4 or 5
OSRaspberry Pi OS 64-bit
NetworkEthernet recommended
RouterPort forwarding capability
Public IPPublic IPv4 or suitable IPv6 setup
VPNWireGuard
ClientWindows, macOS, Linux, Android, or iOS

You’ll also need administrative access to your router.


Before Installing WireGuard

There are two important things to check.

1. Does your ISP use CGNAT?

Your router needs to be reachable from the Internet for a traditional self-hosted VPN server.

Some ISPs place customers behind Carrier-Grade NAT (CGNAT).

If you’re behind CGNAT, configuring port forwarding on your router may not be enough because your router doesn’t have a directly reachable public IPv4 address.

A quick way to investigate is to compare:

  • Your router’s WAN IPv4 address
  • The public IPv4 address shown by an external IP-checking service

If they don’t match, CGNAT is one possible explanation.

Other possibilities include multiple routers or upstream NAT.

If your ISP uses CGNAT, consider:

  • Tailscale
  • A VPS-based WireGuard setup
  • Asking your ISP for a public IPv4 address

Tailscale is particularly convenient because it doesn’t require traditional inbound port forwarding.


2. Give the Raspberry Pi a Stable IP

Your Raspberry Pi should have a stable LAN address.

For example:

Raspberry Pi
192.168.1.50

The easiest approach for many home networks is a DHCP reservation on your router.

This ensures the router always gives the Raspberry Pi the same IP.


Step 1: Update Raspberry Pi OS

Connect to the Raspberry Pi using SSH or a local terminal.

Run:

sudo apt update
sudo apt full-upgrade -y

Then reboot:

sudo reboot

Reconnect after the Raspberry Pi starts.


Step 2: Install WireGuard

On current Debian-based Raspberry Pi OS installations, WireGuard can be installed from the package repository.

Run:

sudo apt install wireguard wireguard-tools -y

WireGuard’s official installation documentation provides package-based installation instructions for Debian and other supported distributions. (WireGuard)

Verify the installation:

wg --version

You should receive a WireGuard version number.


Step 3: Enable IP Forwarding

The Raspberry Pi needs to route traffic between the WireGuard VPN interface and your normal network interface.

Edit the sysctl configuration:

sudo nano /etc/sysctl.d/99-wireguard.conf

Add:

net.ipv4.ip_forward=1

If you’re also configuring IPv6 routing, add:

net.ipv6.conf.all.forwarding=1

Save the file.

Apply the configuration:

sudo sysctl --system

Verify IPv4 forwarding:

sysctl net.ipv4.ip_forward

You should see:

net.ipv4.ip_forward = 1

IP forwarding is a fundamental part of configuring a Raspberry Pi as a VPN gateway. (Raspberry Pi Forums)


Step 4: Create the WireGuard Directory

WireGuard configuration files are normally stored under:

/etc/wireguard/

Create it if necessary:

sudo mkdir -p /etc/wireguard

Protect the directory:

sudo chmod 700 /etc/wireguard

Step 5: Generate the Server Keys

WireGuard uses public/private key pairs for authentication.

Change into the WireGuard directory:

cd /etc/wireguard

Set restrictive permissions:

sudo umask 077

Generate the server private key:

sudo wg genkey | sudo tee server_private.key

Generate the corresponding public key:

sudo cat server_private.key | wg pubkey | sudo tee server_public.key

Check the files:

sudo ls -l /etc/wireguard

You should have:

server_private.key
server_public.key

Never publish your private key.

The public key can be shared with clients.


Step 6: Generate a Client Key Pair

We’ll create one VPN client for a laptop or phone.

Generate its private key:

sudo wg genkey | sudo tee client1_private.key

Generate the public key:

sudo cat client1_private.key | wg pubkey | sudo tee client1_public.key

Now you have:

Server:
server_private.key
server_public.key

Client:
client1_private.key
client1_public.key

Step 7: Create the WireGuard Server Configuration

Create:

sudo nano /etc/wireguard/wg0.conf

Use this as a starting point:

[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY

PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE

[Peer]
PublicKey = CLIENT1_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32

Replace:

SERVER_PRIVATE_KEY

with the contents of:

sudo cat /etc/wireguard/server_private.key

And replace:

CLIENT1_PUBLIC_KEY

with:

sudo cat /etc/wireguard/client1_public.key

Important

The example assumes your Raspberry Pi connects to the network through:

eth0

Check your interface with:

ip route

You may see:

default via 192.168.1.1 dev eth0

If you’re using Wi-Fi, the interface may instead be:

wlan0

Change the PostUp and PostDown rules accordingly.


Understanding the VPN Address Range

The WireGuard VPN will use:

10.8.0.0/24

The server will be:

10.8.0.1

The first client will be:

10.8.0.2

Additional clients could use:

10.8.0.3
10.8.0.4
10.8.0.5

For example:

WireGuard Server
10.8.0.1

Laptop
10.8.0.2

Phone
10.8.0.3

Tablet
10.8.0.4

Step 8: Protect the Configuration File

Because wg0.conf contains your server’s private key, make sure it isn’t readable by ordinary users.

Run:

sudo chmod 600 /etc/wireguard/wg0.conf

Also protect the key files:

sudo chmod 600 /etc/wireguard/*.key

Step 9: Configure Your Router

Your router needs to forward the WireGuard UDP port to the Raspberry Pi.

The default port in our example is:

UDP 51820

Create a port-forwarding rule:

Protocol: UDP
External Port: 51820
Internal IP: 192.168.1.50
Internal Port: 51820

Replace:

192.168.1.50

with your Raspberry Pi’s actual LAN address.

Recent Raspberry Pi documentation also describes WireGuard deployments using UDP port 51820 and router port forwarding. (Raspberry Pi)


Why UDP?

WireGuard uses UDP rather than TCP.

The default WireGuard listening port is:

51820/UDP

You can change the port if necessary, but there usually isn’t a strong reason to do so.


Step 10: Find Your Public IP Address

Your remote VPN client needs to know how to reach your home network.

You could use your public IP:

203.0.113.50

But residential Internet connections often have dynamic IP addresses.

A better solution is Dynamic DNS (DDNS).

For example:

vpn.example.com

Then your client configuration can use:

Endpoint = vpn.example.com:51820

If your public IP changes, your DDNS service updates the hostname.


Step 11: Create the Client Configuration

Create a client configuration file:

nano client1.conf

Use:

[Interface]
PrivateKey = CLIENT1_PRIVATE_KEY
Address = 10.8.0.2/24
DNS = 1.1.1.1

[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = YOUR_PUBLIC_IP_OR_DDNS:51820
AllowedIPs = 10.8.0.0/24, 192.168.1.0/24
PersistentKeepalive = 25

Replace:

CLIENT1_PRIVATE_KEY

with:

sudo cat /etc/wireguard/client1_private.key

Replace:

SERVER_PUBLIC_KEY

with:

sudo cat /etc/wireguard/server_public.key

And replace:

YOUR_PUBLIC_IP_OR_DDNS

with your public IP or DDNS hostname.


What Does AllowedIPs Do?

This is one of the most important WireGuard settings.

Our example:

AllowedIPs = 10.8.0.0/24, 192.168.1.0/24

means that traffic destined for:

10.8.0.0/24

or:

192.168.1.0/24

goes through the VPN.

This is called a split-tunnel configuration.

It allows you to access your home network while normal Internet traffic continues to use the client’s regular Internet connection.


Full-Tunnel VPN Configuration

You can instead route all IPv4 Internet traffic through your home VPN.

Change:

AllowedIPs = 10.8.0.0/24, 192.168.1.0/24

to:

AllowedIPs = 0.0.0.0/0

You can include IPv6:

AllowedIPs = 0.0.0.0/0, ::/0

Now the traffic flow becomes:

Laptop
   │
   │ WireGuard
   ▼
Raspberry Pi
   │
   ▼
Home Router
   │
   ▼
Internet

This makes the remote device appear to access the Internet through your home connection.

For a simple home-network VPN, however, split tunneling is often the better starting point.


Step 12: Start WireGuard

Start the VPN:

sudo wg-quick up wg0

Check its status:

sudo wg show

You should see something similar to:

interface: wg0
  public key: ...
  listening port: 51820

peer: ...
  allowed ips: 10.8.0.2/32

Step 13: Start WireGuard Automatically

Enable the service at boot:

sudo systemctl enable wg-quick@wg0

You can also start it through systemd:

sudo systemctl start wg-quick@wg0

Check:

sudo systemctl status wg-quick@wg0

Step 14: Install WireGuard on Your Client

Install the official WireGuard client on your device.

WireGuard provides clients for major desktop and mobile platforms. (WireGuard)

You can use:

  • Windows
  • macOS
  • Linux
  • Android
  • iPhone/iPad

Step 15: Import the Client Configuration

You have several options.

Desktop

Import:

client1.conf

into the WireGuard application.

Mobile

You can transfer the configuration to your phone or generate a QR code.

QR codes are particularly convenient for phones.


Step 16: Generate a QR Code

Install qrencode:

sudo apt install qrencode -y

Then generate a QR code from the configuration:

qrencode -t ansiutf8 < client1.conf

The terminal will display a QR code.

Open the WireGuard mobile application and choose:

Add a tunnel → Scan from QR code

Scan the displayed code.

Security warning

The QR code contains the client’s private key and VPN configuration.

Treat it as sensitive information.

Don’t post it publicly or send it to people you don’t trust.


Step 17: Activate the VPN

Activate the newly imported WireGuard tunnel.

The client should connect to:

YOUR_PUBLIC_IP_OR_DDNS:51820

If everything is configured correctly, the client will establish a handshake with the Raspberry Pi.


Step 18: Check the WireGuard Handshake

On the Raspberry Pi:

sudo wg show

Look for:

latest handshake

You should see a recent timestamp.

You may also see:

transfer: 12.34 KiB received, 15.67 KiB sent

This confirms that encrypted traffic is flowing through the tunnel.


Step 19: Test the VPN

From the remote client, try:

ping 10.8.0.1

You should receive a response from the WireGuard server.

Then try your Raspberry Pi’s LAN IP:

ping 192.168.1.50

If your routing and firewall configuration are correct, the Raspberry Pi should respond.


Step 20: Access Your Home Network

Now try accessing another device on your LAN.

For example:

192.168.1.100

You could potentially access:

http://192.168.1.100

or:

\\192.168.1.100

depending on the service.

This is where a Raspberry Pi WireGuard server becomes particularly useful.


Access CasaOS Remotely

If CasaOS is running on the Raspberry Pi, you can access:

http://192.168.1.50

through the VPN.

Your traffic follows:

Remote Laptop
      │
  WireGuard
      │
      ▼
Raspberry Pi
      │
    CasaOS

No public CasaOS port needs to be exposed.


Access Jellyfin Remotely

If Jellyfin runs on:

192.168.1.50:8096

you can use:

http://192.168.1.50:8096

while connected to the VPN.

This is an excellent way to keep a personal Jellyfin server private.


Access Nextcloud Remotely

Similarly, if Nextcloud is running on your Raspberry Pi:

https://192.168.1.50

or your internal hostname can be used through the VPN.

Nextcloud may require the VPN-accessible hostname or IP to be included in its trusted_domains configuration.


Use WireGuard with Pi-hole

WireGuard and Pi-hole make a particularly useful combination.

You can configure the client to use your Pi-hole as DNS.

For example:

[Interface]
PrivateKey = CLIENT1_PRIVATE_KEY
Address = 10.8.0.2/24
DNS = 192.168.1.50

Now DNS requests from the VPN client can go through Pi-hole.

The architecture becomes:

Remote Phone
     │
 WireGuard
     │
     ▼
Raspberry Pi
     │
   Pi-hole
     │
     ▼
   Internet

This can give you network-wide DNS filtering even when you’re away from home.


Full-Tunnel VPN with Pi-hole

If you want all traffic to go through your home connection, use:

AllowedIPs = 0.0.0.0/0

and:

DNS = 192.168.1.50

The result is:

Remote Device
      │
      │ WireGuard
      ▼
Raspberry Pi
      │
      ├── Pi-hole DNS
      │
      ▼
 Home Router
      │
      ▼
  Internet

This requires the Raspberry Pi’s NAT and forwarding configuration to be correct.


WireGuard Firewall Configuration

If you’re using a firewall such as UFW, allow the WireGuard UDP port:

sudo ufw allow 51820/udp

Then check:

sudo ufw status

However, don’t blindly enable UFW on a remote Raspberry Pi without understanding its existing rules. You can accidentally lock yourself out of SSH.


WireGuard and nftables

Modern Raspberry Pi OS releases use the Linux networking stack with nftables underneath the system firewall tooling.

If you encounter NAT or forwarding problems, don’t assume that an older iptables-only tutorial will work exactly as written.

Check the current firewall configuration:

sudo nft list ruleset

The exact rules you need depend on your Raspberry Pi OS version, firewall configuration, and whether you’re using iptables compatibility tools.


Why VPN Clients Can’t Access the Internet

A common problem is:

“The VPN connects, but I can’t browse the Internet.”

This usually happens when:

  • IP forwarding isn’t enabled.
  • NAT isn’t configured.
  • The wrong interface is specified.
  • Firewall forwarding is blocked.
  • AllowedIPs is incorrect.

Check forwarding:

sysctl net.ipv4.ip_forward

You want:

net.ipv4.ip_forward = 1

Then check the default interface:

ip route

You might see:

default via 192.168.1.1 dev eth0

In that case, eth0 is the interface connected to your LAN/Internet.


Why the VPN Connects but LAN Devices Don’t Work

If the VPN handshake succeeds but you can’t access:

192.168.1.x

check:

Client AllowedIPs

Make sure the client includes:

AllowedIPs = 10.8.0.0/24, 192.168.1.0/24

IP forwarding

Check:

sysctl net.ipv4.ip_forward

Firewall

Make sure forwarding isn’t blocked.

Return routing

The LAN device needs a route back to the VPN network.

NAT on the Raspberry Pi can simplify this because the LAN devices see traffic as coming from the Raspberry Pi’s LAN address.


Why the Client Can’t Connect at All

If there is no handshake, check the following.

Port forwarding

Make sure:

UDP 51820

is forwarded to the Raspberry Pi.

Public IP

Verify your endpoint is correct.

DDNS

If your public IP changes, confirm that your hostname points to the current address.

CGNAT

If your ISP uses CGNAT, traditional inbound WireGuard may not work.

Firewall

Make sure UDP 51820 isn’t being blocked.


How to Check the Listening Port

Run:

sudo ss -lunp | grep 51820

You should see WireGuard listening on UDP port 51820.


Monitor WireGuard

The most useful command is:

sudo wg show

It provides:

  • Interface
  • Public key
  • Listening port
  • Peers
  • Latest handshake
  • Transfer statistics
  • Allowed IPs

For troubleshooting, this should be one of your first commands.


Generate Additional Clients

You should create a unique key pair for every device.

For example:

Laptop
10.8.0.2

Phone
10.8.0.3

Tablet
10.8.0.4

Don’t reuse the same client private key across multiple devices.


Add a Second Client

Generate another key:

cd /etc/wireguard

sudo wg genkey | sudo tee phone_private.key
sudo cat phone_private.key | wg pubkey | sudo tee phone_public.key

Add another peer to:

/etc/wireguard/wg0.conf

For example:

[Peer]
PublicKey = PHONE_PUBLIC_KEY
AllowedIPs = 10.8.0.3/32

Then restart WireGuard:

sudo systemctl restart wg-quick@wg0

WireGuard Configuration Structure

The server configuration might eventually look like:

[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY

PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE

[Peer]
PublicKey = LAPTOP_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32

[Peer]
PublicKey = PHONE_PUBLIC_KEY
AllowedIPs = 10.8.0.3/32

[Peer]
PublicKey = TABLET_PUBLIC_KEY
AllowedIPs = 10.8.0.4/32

Each peer gets its own VPN address.


Use PersistentKeepalive for Mobile Devices

Mobile devices often move between networks and may sit behind NAT.

In the client configuration:

PersistentKeepalive = 25

can help maintain connectivity through NAT devices.

This is especially useful for phones and laptops that frequently switch between Wi-Fi and cellular networks.


WireGuard Security Recommendations

A VPN server is still an Internet-facing service.

Follow these practices:

Keep Raspberry Pi OS updated

sudo apt update
sudo apt full-upgrade

Protect private keys

Never publish:

server_private.key
client_private.key

Use unique keys

Every device should have its own key pair.

Remove lost devices

If a phone or laptop is lost, remove its peer configuration from the server.

Don’t expose unnecessary ports

Ideally, your router only needs the WireGuard UDP port for remote VPN access.

Use strong SSH security

Don’t expose SSH unnecessarily if you don’t need public SSH access.


WireGuard vs Tailscale

If you’re deciding between WireGuard and Tailscale, both are excellent options, but they solve the problem differently.

FeatureWireGuardTailscale
Open source protocolYesUses WireGuard
Manual configurationRequiredMinimal
Port forwardingUsually requiredUsually not
Public IP requiredUsuallyNo for normal use
CGNAT friendlyNot directlyYes
Device managementManualExcellent
Subnet routingYesYes
Raspberry PiExcellentExcellent
Beginner friendlyModerateExcellent
Maximum controlExcellentVery good

Choose WireGuard if:

  • You want complete control.
  • You have a public IP.
  • You can configure port forwarding.
  • You want to learn VPN networking.
  • You want a minimal VPN implementation.

Choose Tailscale if:

  • Your ISP uses CGNAT.
  • You don’t want to configure port forwarding.
  • You have multiple devices.
  • You want easy device management.
  • You want a simpler setup.

For a beginner building a Raspberry Pi home server, Tailscale is usually easier. For someone who wants to learn and control the entire VPN infrastructure, WireGuard is an excellent choice.


WireGuard vs OpenVPN

WireGuard is generally simpler to configure than traditional OpenVPN deployments.

FeatureWireGuardOpenVPN
ConfigurationSimpleMore complex
PerformanceExcellentGood
Modern cryptographyYesYes
CodebaseSmallLarger
Mobile supportExcellentExcellent
Raspberry PiExcellentExcellent
Ease of setup⭐⭐⭐⭐⭐⭐⭐⭐

For a new Raspberry Pi VPN server, WireGuard is generally the more attractive option.


Should You Use PiVPN?

If you don’t want to manually create keys and configuration files, PiVPN is another option worth considering.

PiVPN provides an installer and management commands designed to simplify VPN deployment on Raspberry Pi and Debian-based systems.

For example, the Raspberry Pi documentation has demonstrated PiVPN with WireGuard using:

curl -L https://install.pivpn.io | bash

and then creating VPN clients with:

pivpn add

(Raspberry Pi)

For this article, however, we used a manual WireGuard installation because it gives you a better understanding of how the VPN works.


WireGuard with CasaOS

If your Raspberry Pi already runs CasaOS, WireGuard can provide remote access to your services.

For example:

                    Internet
                       │
                    WireGuard
                       │
                       ▼
                Raspberry Pi 5
                       │
                     CasaOS
                       │
         ┌─────────────┼─────────────┐
         │             │             │
      Jellyfin      Nextcloud     Pi-hole

This is a particularly strong home-server architecture.

You can keep your applications private while accessing them remotely through the VPN.


WireGuard with Jellyfin

For a private Jellyfin installation, WireGuard can be preferable to exposing Jellyfin directly to the Internet.

Instead of:

Internet
   │
Port 8096
   │
Jellyfin

use:

Phone
 │
WireGuard
 │
Raspberry Pi
 │
Jellyfin

This is particularly useful for personal and family media servers.


WireGuard with Nextcloud

The same approach works with Nextcloud.

Your remote laptop connects to your home VPN:

Laptop
   │
WireGuard
   │
Raspberry Pi
   │
Nextcloud
   │
SSD

You can then access Nextcloud using its private address without necessarily exposing the application publicly.


WireGuard as a Remote Home-Lab VPN

One of the best uses for a Raspberry Pi WireGuard server is remote administration.

Imagine you’re traveling and need access to:

  • Proxmox
  • NAS
  • Raspberry Pi
  • Home Assistant
  • Router
  • Switch
  • Internal websites

Instead of exposing each service individually:

Internet
 │
 ├── NAS port
 ├── Home Assistant port
 ├── SSH port
 ├── Proxmox port
 └── Other ports

you can expose only:

Internet
   │
UDP 51820
   │
Raspberry Pi
   │
VPN
   │
Home LAN

This is much cleaner.


Backup Your WireGuard Configuration

Your WireGuard configuration contains important private keys.

Back up:

/etc/wireguard/

but protect the backup carefully.

You don’t want your private keys stored in an unsecured public repository.

A backup should include:

  • wg0.conf
  • Server private key
  • Client configurations
  • Client keys
  • Documentation of your network settings

What Happens If the Raspberry Pi Reboots?

If you’ve enabled:

sudo systemctl enable wg-quick@wg0

WireGuard should start automatically when the system boots.

Check:

sudo systemctl status wg-quick@wg0

This is important for a VPN server because you don’t want to manually start the service after every power outage.


Troubleshooting Checklist

If your WireGuard VPN isn’t working, go through this list.

Server

sudo wg show

Service

sudo systemctl status wg-quick@wg0

Listening port

sudo ss -lunp | grep 51820

IP forwarding

sysctl net.ipv4.ip_forward

Routing

ip route

Network interface

ip addr

Firewall

sudo nft list ruleset

Router

Verify:

UDP 51820 → Raspberry Pi

Client

Check:

  • Public endpoint
  • Server public key
  • Client private key
  • AllowedIPs
  • VPN address
  • DNS
  • PersistentKeepalive

Important: CGNAT Can Break This Setup

One of the most important limitations of hosting your own VPN at home is CGNAT.

If your ISP gives your router a private or shared WAN address and places your connection behind another layer of NAT, an incoming WireGuard connection may never reach your Raspberry Pi.

In that situation, you can consider:

Option 1: Tailscale

Easy and generally works without inbound port forwarding.

Option 2: Ask your ISP for a public IP

Some ISPs offer this as an option.

Option 3: Use a VPS

Deploy WireGuard on a VPS and establish a connection between your home network and the VPS.

This is more advanced but provides greater control.


Is a Raspberry Pi Good for a VPN Server?

Yes.

A Raspberry Pi is an excellent platform for a personal WireGuard server.

It’s particularly useful for:

  • Remote home access
  • Home labs
  • Secure SSH access
  • Accessing NAS devices
  • Jellyfin
  • Nextcloud
  • Home Assistant
  • Pi-hole
  • Internal websites

The Raspberry Pi doesn’t need to be especially powerful for a normal VPN workload.

The more important factors are:

  • Internet bandwidth
  • Network configuration
  • Router capabilities
  • ISP limitations
  • VPN routing
  • Firewall configuration

Recommended Raspberry Pi VPN Setup

For a typical home server, I’d use:

                 Internet
                     │
               UDP 51820
                     │
                     ▼
                 Router
                     │
                     ▼
              Raspberry Pi 5
                     │
                 WireGuard
                     │
              10.8.0.0/24
                     │
        ┌────────────┼────────────┐
        │            │            │
      Laptop        Phone       Tablet
        │
        └──────── Home LAN ────────┐
                                   │
                         ┌─────────┼─────────┐
                         │         │         │
                       NAS     Home Assistant  PC

For the best experience, connect the Raspberry Pi to your router through Gigabit Ethernet.


Final Thoughts

A Raspberry Pi running WireGuard can provide a secure and inexpensive way to access your home network remotely.

The basic architecture is simple:

Remote Device
      │
      │ Encrypted WireGuard Tunnel
      ▼
  Home Router
      │
      ▼
 Raspberry Pi
      │
      ▼
  Home Network

The most important parts of the configuration are:

  1. Give the Raspberry Pi a stable LAN address.
  2. Install WireGuard.
  3. Enable IP forwarding.
  4. Generate unique keys.
  5. Configure wg0.conf.
  6. Forward UDP 51820 on your router.
  7. Configure your client.
  8. Test the WireGuard handshake.
  9. Configure routing and NAT.
  10. Secure your private keys.

If your ISP supports inbound connections, WireGuard is an excellent choice for a self-hosted Raspberry Pi VPN.

If your ISP uses CGNAT or you want a much simpler setup, consider Tailscale instead.

For the home-server ecosystem you’re building, a particularly useful combination is:

Raspberry Pi + CasaOS + WireGuard + Jellyfin + Nextcloud + Pi-hole

This gives you a low-power server that you can securely manage and access from almost anywhere.


Frequently Asked Questions

Can I use a Raspberry Pi as a VPN server?

Yes. Raspberry Pi OS supports WireGuard, making the Raspberry Pi a practical VPN server for personal and home-lab use. (WireGuard)

Is WireGuard free?

Yes. WireGuard is free and open-source software.

What port does WireGuard use?

The default WireGuard port is UDP 51820.

Do I need to forward port 51820?

For a conventional self-hosted WireGuard server behind a home router, yes, you normally need to forward the WireGuard UDP port to the Raspberry Pi.

Can I use WireGuard without port forwarding?

Not in the conventional direct-to-home-server setup. If you cannot accept inbound connections, Tailscale or another NAT-traversing solution may be a better choice.

Can I access my entire home network?

Yes. With appropriate routing and firewall configuration, the Raspberry Pi can provide VPN clients access to your LAN.

Can WireGuard route all Internet traffic through my home?

Yes. Configure the client with:

AllowedIPs = 0.0.0.0/0

and configure forwarding/NAT correctly on the Raspberry Pi.

Is WireGuard better than Tailscale?

Neither is universally better. WireGuard gives you more direct control and a simpler underlying protocol, while Tailscale makes device management and NAT traversal much easier.

Can I run WireGuard and Tailscale on the same Raspberry Pi?

Yes, but you should understand the routing and firewall interactions before doing so. For a beginner, it’s usually simpler to choose one VPN solution for a particular purpose.


Recommended Links