whatis wireguard
WireGuard
Also known as: wg, wg-quick
A fast, modern VPN protocol built into the Linux kernel, configured with short key-based config files.
What Is WireGuard in Linux?
WireGuard creates an encrypted tunnel interface (like wg0) between peers identified by public keys. Its codebase is tiny compared to OpenVPN or IPsec, it roams seamlessly between networks, and it has been in the mainline kernel since 5.6.
Tailscale, Headscale, and similar mesh VPNs use WireGuard underneath and automate key exchange and NAT traversal.
Example
wg genkey | tee private.key | wg pubkey > public.key
sudo wg-quick up wg0 Learn more about WireGuard
- WireGuard Explained: The Modern Linux VPN WireGuard is a VPN protocol built into the Linux kernel: a few thousand lines of code, public-key pairs instead of certificate bureaucracy, and configs short enough to read. Here is how it works and a working two-peer setup.
- WireGuard vs OpenVPN vs Tailscale: Choosing a VPN for a Homelab Three tools, three different problems. One is a protocol, one is an older protocol with more options, and one is a coordination layer that removes the hard part. Here is which to use when.
- Headscale: Self-Hosting the Tailscale Control Plane What the coordination server actually does, why self-hosting it removes the one third party in a WireGuard mesh, and what you give up by leaving the commercial service.
Related tools
- WireGuard Config Generator Produce matching server and peer configs with AllowedIPs, DNS, keepalive, and NAT forwarding rules.