Black Friday Our biggest deal of the year is coming soon Get notified →

Setting Up WireGuard on OPNsense with PremierVPN

Updated 4 Oct 2026 6 min read

This guide shows you how to connect an OPNsense firewall to your PremierVPN Dedicated WireGuard Server, so devices on your network go out through your server's IP. You can send your whole LAN through the tunnel or only chosen devices.

What you need

  • OPNsense with WireGuard. Current releases include WireGuard as standard. On older releases, install the os-wireguard plugin from System › Firmware › Plugins. Menu names below match current releases and may differ slightly on older ones.
  • A PremierVPN Dedicated WireGuard Server assigned to your account. It appears under WireGuard in the portal sidebar.
  • A WireGuard user for the router. Each device needs its own user, so create one just for OPNsense. See Creating and managing WireGuard users.

This guide uses WireGuard keys, not your VPN username and password.

Step 1: Get your configuration from the portal

  1. In the portal, open WireGuard and click Manage Server.
  2. Under Create WireGuard User, enter a name such as opnsense (letters, numbers, hyphens and underscores only) and click Create User.
  3. On the new user's row, click .conf to download the configuration file, and click Keys to see the Client Public Key. You'll need both.

The file looks like this (your keys, addresses and port will differ):

[Interface]
PrivateKey = aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789...
Address = 10.66.66.2/32
DNS = 1.1.1.1, 8.8.8.8

[Peer]
PublicKey = xYzAbCdEfGhIjKlMnOpQrStUvWxYz9876543...
PresharedKey = pQrStUvWxYz0123456789aBcDeFgHiJkLmN...
Endpoint = 203.0.113.10:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

Your server's own tunnel address is the .1 address in the same range as your Address. In the example above that's 10.66.66.1. You'll use it as the gateway.

Step 2: Create the WireGuard instance

The instance is your router's end of the tunnel.

  1. Go to VPN › WireGuard › Instances and click +.
  2. Fill in:
    FieldValue
    Namepremiervpn
    Private keyThe PrivateKey from the [Interface] section
    Public keyThe Client Public Key from the portal's Keys panel
    Listen portAny unused port, for example 51821 (this is local, not the server's port)
    Tunnel addressThe Address, for example 10.66.66.2/32
    Disable routesTicked, so only the traffic you choose uses the tunnel
    GatewayThe server's tunnel address, for example 10.66.66.1 (leave empty if your version doesn't show this field)
  3. Click Save.

Step 3: Add the PremierVPN server as a peer

  1. Go to VPN › WireGuard › Peers and click +.
  2. Fill in:
    FieldValue
    NamePremierVPN
    Public keyThe PublicKey from the [Peer] section
    Pre-shared keyThe PresharedKey from the [Peer] section, if your file has one
    Allowed IPs0.0.0.0/0
    Endpoint addressThe IP address part of Endpoint, for example 203.0.113.10
    Endpoint portThe port part of Endpoint, for example 51820
    InstancesSelect premiervpn
    Keepalive interval25
  3. Click Save.
  4. Tick Enable WireGuard and click Apply.

On some older versions the peer has no Instances field. In that case, edit the instance and select the peer under Peers instead.

Step 4: Assign the WireGuard interface

  1. Go to Interfaces › Assignments.
  2. Pick the new WireGuard device (for example wg0, labelled with your instance name), give it the description WG_PREMIERVPN and click Add.
  3. Open the new interface, tick Enable Interface and click Save, then Apply changes. Leave the IPv4 and IPv6 configuration types as None: the instance already sets the address.

Step 5: Create the gateway

  1. Go to System › Gateways › Configuration and click +.
  2. Fill in:
    FieldValue
    NameWG_PREMIERVPN_GW
    InterfaceWG_PREMIERVPN
    Address familyIPv4
    IP addressThe server's tunnel address, for example 10.66.66.1
    Far gatewayTicked
    Disable gateway monitoringTicked for now. Untick it later if you set up the kill switch below.
  3. Click Save, then Apply.

Step 6: Add an outbound NAT rule

  1. Go to Firewall › NAT › Outbound.
  2. If the mode is Automatic outbound NAT rule generation, switch to Hybrid outbound NAT rule generation and click Save.
  3. Click + and set Interface to WG_PREMIERVPN, Source address to LAN net (or the network you want to route), and Translation / target to Interface address. Leave the rest as Any.
  4. Click Save, then Apply changes.

Step 7: Send LAN traffic through the tunnel

  1. Go to Firewall › Rules › LAN and click +.
  2. Set Action to Pass, Protocol to any, Source to LAN net, Destination to any, and under advanced options set Gateway to WG_PREMIERVPN_GW.
  3. Click Save, drag the rule above the default LAN pass rules, then click Apply changes.
If this rule sits below the default "LAN net to any" rule, traffic keeps using your normal internet connection.

If you need to reach the firewall itself or other local networks from the LAN, add pass rules for those destinations above this one, without a gateway set.

Step 8: Stop DNS leaks

Choose one of these:

  • If you use Unbound DNS (the default resolver): go to Services › Unbound DNS › General, set Outgoing Network Interfaces to WG_PREMIERVPN, save and apply.
  • If you forward to fixed DNS servers: go to System › Settings › General, add 1.1.1.1 and 8.8.8.8 with the gateway WG_PREMIERVPN_GW, untick Allow DNS server list to be overridden by DHCP/PPP on WAN, and save.

Either way, the router's own DNS lookups go through the tunnel, so they stop working if the tunnel is down.

Step 9: Check it works

  1. Go to VPN › WireGuard › Status and check the PremierVPN peer shows a recent handshake.
  2. In the portal's Manage Server page, your opnsense user should show as Online.
  3. From a device on your LAN, open the IP leak test. It should show your dedicated server's IP and no DNS servers from your internet provider.

Optional: route only some devices

  1. Go to Firewall › Aliases and create a Host(s) alias, for example VPN_Devices, with the LAN IPs of the devices you want on the VPN. Give those devices fixed IPs (DHCP reservations) so the alias stays correct.
  2. Edit the LAN rule from Step 7 and change Source from LAN net to VPN_Devices.
  3. Do the same in the outbound NAT rule from Step 6 if you want to be strict.

Other devices keep using your normal connection.

Optional: kill switch

By default, if the tunnel goes down, OPNsense sends policy-routed traffic out of your normal WAN. To block it instead:

  1. Go to Firewall › Settings › Advanced, tick Skip rules when gateway is down and save.
  2. Edit WG_PREMIERVPN_GW: untick Disable gateway monitoring and set Monitor IP to a public address such as 1.1.1.1, so OPNsense can tell when the tunnel is down.
  3. In Firewall › Rules › LAN, add a Block rule with the same source (LAN net or VPN_Devices) and destination any. Place it directly below the VPN pass rule and above the default LAN pass rules.

Now, when the gateway is down, the VPN rule is skipped and the block rule stops the traffic.

Troubleshooting

No handshake

  • Check the keys were copied exactly, with no missing characters. The instance takes the client keys; the peer takes the server public key and pre-shared key.
  • Check the endpoint address and port match the Endpoint line.
  • Make sure nothing upstream blocks outbound UDP to the server's port.
  • Untick Enable WireGuard, apply, then tick it again and apply.

Handshake works but no internet

  • Check the outbound NAT rule (Step 6) uses the WG_PREMIERVPN interface.
  • Check the LAN rule (Step 7) uses the WG_PREMIERVPN_GW gateway and sits above the default pass rules.
  • Check DNS (Step 8).
  • Look in Firewall › Diagnostics › States for traffic on the WireGuard interface.

Some websites hang or load slowly

Set MTU to 1420 on the instance. If pages still stall, lower it further (for example 1380).

Connection drops now and then

Make sure Keepalive interval on the peer is 25, and check VPN › WireGuard › Log File for errors.

FAQs

Can I use this with a shared VPN plan?

Not this guide. WireGuard configuration files and keys come with a Dedicated WireGuard Server. On a shared plan you can use OPNsense's OpenVPN client with an .ovpn file from the Servers page and your VPN username and password.

What if my server's IP address changes?

Update the Endpoint address on the peer. The current endpoint is always shown in the portal under Keys for your user.

Can I run this alongside OpenVPN, or in a virtual machine?

Yes. WireGuard and OpenVPN use separate interfaces and can run side by side. OPNsense in a virtual machine works the same way as long as its LAN and WAN interfaces are set up correctly.

Still stuck? Open a support ticket and tell us your OPNsense version, whether you see a handshake, and what you've tried.

Something out of date or unclear? Let us know.

Stay Ahead of Online Threats

Get VPN tips, security insights, and exclusive offers delivered straight to your inbox. No spam — just the essentials.

Unsubscribe at any time. We respect your privacy.

PremierVPN Support