This guide shows you how to connect an OPNsense firewall to your PremierVPN Dedicated WireGuard Server, so devices on your network go out through your server's IP. You can send your whole LAN through the tunnel or only chosen devices.
What you need
- OPNsense with WireGuard. Current releases include WireGuard as standard. On older releases, install the
os-wireguardplugin from System › Firmware › Plugins. Menu names below match current releases and may differ slightly on older ones. - A PremierVPN Dedicated WireGuard Server assigned to your account. It appears under WireGuard in the portal sidebar.
- A WireGuard user for the router. Each device needs its own user, so create one just for OPNsense. See Creating and managing WireGuard users.
This guide uses WireGuard keys, not your VPN username and password.
Step 1: Get your configuration from the portal
- In the portal, open WireGuard and click Manage Server.
- Under Create WireGuard User, enter a name such as
opnsense(letters, numbers, hyphens and underscores only) and click Create User. - On the new user's row, click .conf to download the configuration file, and click Keys to see the Client Public Key. You'll need both.
The file looks like this (your keys, addresses and port will differ):
[Interface]
PrivateKey = aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789...
Address = 10.66.66.2/32
DNS = 1.1.1.1, 8.8.8.8
[Peer]
PublicKey = xYzAbCdEfGhIjKlMnOpQrStUvWxYz9876543...
PresharedKey = pQrStUvWxYz0123456789aBcDeFgHiJkLmN...
Endpoint = 203.0.113.10:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
Your server's own tunnel address is the .1 address in the same range as your Address. In the example above that's 10.66.66.1. You'll use it as the gateway.
Step 2: Create the WireGuard instance
The instance is your router's end of the tunnel.
- Go to VPN › WireGuard › Instances and click +.
- Fill in:
Field Value Name premiervpnPrivate key The PrivateKeyfrom the[Interface]sectionPublic key The Client Public Key from the portal's Keys panel Listen port Any unused port, for example 51821(this is local, not the server's port)Tunnel address The Address, for example10.66.66.2/32Disable routes Ticked, so only the traffic you choose uses the tunnel Gateway The server's tunnel address, for example 10.66.66.1(leave empty if your version doesn't show this field) - Click Save.
Step 3: Add the PremierVPN server as a peer
- Go to VPN › WireGuard › Peers and click +.
- Fill in:
Field Value Name PremierVPNPublic key The PublicKeyfrom the[Peer]sectionPre-shared key The PresharedKeyfrom the[Peer]section, if your file has oneAllowed IPs 0.0.0.0/0Endpoint address The IP address part of Endpoint, for example203.0.113.10Endpoint port The port part of Endpoint, for example51820Instances Select premiervpnKeepalive interval 25 - Click Save.
- Tick Enable WireGuard and click Apply.
On some older versions the peer has no Instances field. In that case, edit the instance and select the peer under Peers instead.
Step 4: Assign the WireGuard interface
- Go to Interfaces › Assignments.
- Pick the new WireGuard device (for example
wg0, labelled with your instance name), give it the descriptionWG_PREMIERVPNand click Add. - Open the new interface, tick Enable Interface and click Save, then Apply changes. Leave the IPv4 and IPv6 configuration types as None: the instance already sets the address.
Step 5: Create the gateway
- Go to System › Gateways › Configuration and click +.
- Fill in:
Field Value Name WG_PREMIERVPN_GWInterface WG_PREMIERVPNAddress family IPv4 IP address The server's tunnel address, for example 10.66.66.1Far gateway Ticked Disable gateway monitoring Ticked for now. Untick it later if you set up the kill switch below. - Click Save, then Apply.
Step 6: Add an outbound NAT rule
- Go to Firewall › NAT › Outbound.
- If the mode is Automatic outbound NAT rule generation, switch to Hybrid outbound NAT rule generation and click Save.
- Click + and set Interface to
WG_PREMIERVPN, Source address toLAN net(or the network you want to route), and Translation / target to Interface address. Leave the rest as Any. - Click Save, then Apply changes.
Step 7: Send LAN traffic through the tunnel
- Go to Firewall › Rules › LAN and click +.
- Set Action to Pass, Protocol to any, Source to
LAN net, Destination to any, and under advanced options set Gateway toWG_PREMIERVPN_GW. - Click Save, drag the rule above the default LAN pass rules, then click Apply changes.
If this rule sits below the default "LAN net to any" rule, traffic keeps using your normal internet connection.
If you need to reach the firewall itself or other local networks from the LAN, add pass rules for those destinations above this one, without a gateway set.
Step 8: Stop DNS leaks
Choose one of these:
- If you use Unbound DNS (the default resolver): go to Services › Unbound DNS › General, set Outgoing Network Interfaces to
WG_PREMIERVPN, save and apply. - If you forward to fixed DNS servers: go to System › Settings › General, add
1.1.1.1and8.8.8.8with the gatewayWG_PREMIERVPN_GW, untick Allow DNS server list to be overridden by DHCP/PPP on WAN, and save.
Either way, the router's own DNS lookups go through the tunnel, so they stop working if the tunnel is down.
Step 9: Check it works
- Go to VPN › WireGuard › Status and check the
PremierVPNpeer shows a recent handshake. - In the portal's Manage Server page, your
opnsenseuser should show as Online. - From a device on your LAN, open the IP leak test. It should show your dedicated server's IP and no DNS servers from your internet provider.
Optional: route only some devices
- Go to Firewall › Aliases and create a Host(s) alias, for example
VPN_Devices, with the LAN IPs of the devices you want on the VPN. Give those devices fixed IPs (DHCP reservations) so the alias stays correct. - Edit the LAN rule from Step 7 and change Source from
LAN nettoVPN_Devices. - Do the same in the outbound NAT rule from Step 6 if you want to be strict.
Other devices keep using your normal connection.
Optional: kill switch
By default, if the tunnel goes down, OPNsense sends policy-routed traffic out of your normal WAN. To block it instead:
- Go to Firewall › Settings › Advanced, tick Skip rules when gateway is down and save.
- Edit
WG_PREMIERVPN_GW: untick Disable gateway monitoring and set Monitor IP to a public address such as1.1.1.1, so OPNsense can tell when the tunnel is down. - In Firewall › Rules › LAN, add a Block rule with the same source (
LAN netorVPN_Devices) and destination any. Place it directly below the VPN pass rule and above the default LAN pass rules.
Now, when the gateway is down, the VPN rule is skipped and the block rule stops the traffic.
Troubleshooting
No handshake
- Check the keys were copied exactly, with no missing characters. The instance takes the client keys; the peer takes the server public key and pre-shared key.
- Check the endpoint address and port match the
Endpointline. - Make sure nothing upstream blocks outbound UDP to the server's port.
- Untick Enable WireGuard, apply, then tick it again and apply.
Handshake works but no internet
- Check the outbound NAT rule (Step 6) uses the
WG_PREMIERVPNinterface. - Check the LAN rule (Step 7) uses the
WG_PREMIERVPN_GWgateway and sits above the default pass rules. - Check DNS (Step 8).
- Look in Firewall › Diagnostics › States for traffic on the WireGuard interface.
Some websites hang or load slowly
Set MTU to 1420 on the instance. If pages still stall, lower it further (for example 1380).
Connection drops now and then
Make sure Keepalive interval on the peer is 25, and check VPN › WireGuard › Log File for errors.
FAQs
Can I use this with a shared VPN plan?
Not this guide. WireGuard configuration files and keys come with a Dedicated WireGuard Server. On a shared plan you can use OPNsense's OpenVPN client with an .ovpn file from the Servers page and your VPN username and password.
What if my server's IP address changes?
Update the Endpoint address on the peer. The current endpoint is always shown in the portal under Keys for your user.
Can I run this alongside OpenVPN, or in a virtual machine?
Yes. WireGuard and OpenVPN use separate interfaces and can run side by side. OPNsense in a virtual machine works the same way as long as its LAN and WAN interfaces are set up correctly.
Still stuck? Open a support ticket and tell us your OPNsense version, whether you see a handshake, and what you've tried.