Each WireGuard® user on your dedicated server has a .conf file with everything a WireGuard app needs to connect. This article explains each line, so you can check a config or adjust it safely.
Example config
A config downloaded from the portal looks like this:
[Interface]
PrivateKey = cGF0aC90by9wcml2YXRla2V5...
Address = 10.66.66.2/32
DNS = 1.1.1.1, 8.8.8.8
[Peer]
PublicKey = c2VydmVyLXB1YmxpYy1rZXk...
PresharedKey = cHJlc2hhcmVkLWtleS1oZXJl...
Endpoint = 203.0.113.10:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
Your keys, addresses and port will be different. Your server's IP address, WireGuard port and subnet are shown under Server Info on the server page.
The [Interface] section
This section describes your device.
- PrivateKey: your device's private key. It's created when you add the user and stored encrypted in our database. Never share it.
- Address: your device's internal IP address on the server. Each user gets its own.
/32means a single address. - DNS: the DNS servers your device uses while connected. The default is Cloudflare (
1.1.1.1) and Google (8.8.8.8).
The [Peer] section
This section describes your server.
- PublicKey: the server's public key. Your device uses it to make sure it's talking to your server.
- PresharedKey: an extra secret shared only by your device and the server. It adds a second layer of encryption on top of the normal key exchange.
- Endpoint: your server's public IP address and WireGuard port. This is where your device sends its encrypted traffic.
- AllowedIPs: which traffic goes through the tunnel.
0.0.0.0/0, ::/0sends everything, IPv4 and IPv6, through the VPN (full tunnel). - PersistentKeepalive: sends a small packet every 25 seconds. This keeps the connection open through routers and firewalls, which matters if you use port forwarding.
Changing the config
You can edit the file in any text editor before importing it, or edit the tunnel in the WireGuard app.
- Different DNS or a hostname endpoint: use the Custom Config Builder instead of editing by hand. Click Keys next to the user, open Custom Config Builder, choose your DNS servers or enter a hostname, and click Download Custom Config.
- Split tunnelling: change
AllowedIPsto your server's subnet (for example10.66.66.0/24, shown under Server Info › Subnet). Only traffic for the WireGuard network then uses the tunnel, and everything else uses your normal connection. Port forwards still work like this. - MTU: if some sites or apps stall on certain networks, add a line such as
MTU = 1380under[Interface]. If that doesn't help, try1280.
Don't change PrivateKey, PublicKey, PresharedKey or Address. The server only accepts the values it issued.
Keeping your config safe
- Anyone with your config file or private key can connect as that device. Don't post it or share it.
- If you think a config has leaked, remove the user on the server page and create a new one. The new user gets completely new keys, and the old config stops working straight away.
FAQs
Can I use the same config on two devices at once?
Not reliably. WireGuard only tracks one connection per key, so the two devices keep knocking each other off. Create a user for each device.
Will re-downloading the config change it?
No. Downloading the .conf again gives you the same keys and settings.
What if my server's IP address changes?
Your server keeps its IP address. If we ever have to move your server, download the config again or update the Endpoint line.
Still stuck? Open a support ticket and tell us your device, app version and what you've tried.