WireGuard: Your Own VPN for AI Services
What This Article Covers
- What WireGuard is and why it matters for AI services
- How to set up your own VPN server as a gateway
- How to connect clients and securely reach your networks
- What configuration is needed for Ollama and other tools
- Common pitfalls during setup and how to avoid them
Introduction
When you run AI tools like Ollama at home or on a small server, you often want to access them from outside. Instead of exposing individual services directly to the internet, you can use a VPN. A VPN (Virtual Private Network) creates an encrypted tunnel between your device and your server, making your laptop, tablet, or phone appear as if it’s on your home network.
WireGuard is a modern VPN standard. It’s lean, fast, and far simpler to configure than older VPN solutions. For AI services, this means you can keep your Ollama instance on your local network without needing port forwarding or a reverse proxy. Once you connect to WireGuard, you simply address Ollama using its internal IP address.
In this guide, I’ll show you how to install WireGuard on Ubuntu, add your first peers, and securely reach your AI services. Familiarity with Linux and networking basics will help. If you prefer a ready-made mesh solution, consider Tailscale.
Why WireGuard?
WireGuard was built to be fast and easy to understand. The codebase is compact, the cryptography is modern, and performance is excellent. This is a major advantage over traditional solutions like OpenVPN or IPsec, which often come with massive configuration files and complex certificate hierarchies.
For AI services, WireGuard is particularly practical because you don’t need to expose individual services. You connect to the VPN and then access internal IPs directly, like 192.168.1.42:11434. Your home network stays hidden behind the server while remaining accessible from anywhere. You can also route your internet traffic through your home connection or server when traveling, which enables privacy and bypassing filtering.
WireGuard in a Nutshell
WireGuard works with public and private keys. Each participant, called a peer, has a key pair. The server knows the public key of its clients and vice versa. Instead of usernames and passwords, devices authenticate using their keys. The connection runs over UDP and uses port 51820 by default.
Configuration is stored in INI files, one per peer. On Linux, use wg and wg-quick. The wg command is the CLI tool, and wg-quick helps you start and stop tunnels. On mobile devices, official apps can scan a QR code of your key.
Who Should Read This?
This article targets experienced beginners. You should be comfortable with the Linux command line, able to administer an Ubuntu or Debian system, and understand basic networking concepts. If you already have a server, setup takes under an hour. If you’re new to Linux, our Ubuntu Server guide will help.
For an even simpler approach, try Tailscale. It’s also based on WireGuard but handles most administration. Direct WireGuard setup gives you full control and works without external infrastructure.
Key Terms
| Term | Meaning |
|---|---|
| VPN | Virtual Private Network, an encrypted tunnel across a public network. |
| Peer | A participant in the WireGuard network (server or client). |
| Private Key | A secret key that must never be shared. |
| Public Key | The public counterpart to the private key, which you distribute. |
| Endpoint | Your server’s public address and port. |
| AllowedIPs | Specifies which IP addresses are routed through the tunnel. |
| PersistentKeepalive | Keeps NAT connections alive by sending regular packets. |
| Handshake | The connection establishment between two peers. |
| Subnet | An IP address range, such as 10.0.0.0/24. |
Prerequisites and Planning
You need a server running Ubuntu or Debian with root access. The server must have a public IP so clients can connect from outside. Alternatively, you can run WireGuard on a Raspberry Pi on your home network and forward UDP port 51820 in your router to that Pi.
Choose a VPN subnet that won’t collide with your existing networks. A simple range is 10.200.200.0/24. The server gets 10.200.200.1, and clients get 10.200.200.2, 10.200.200.3, and so on. Document each peer so you manage IP addresses and public keys cleanly.
Open UDP port 51820 in your firewall. IP forwarding must also be enabled in the kernel so the server can relay traffic. Instructions for this follow in the next section.
Installing WireGuard
Update your system and install WireGuard:
sudo apt update
sudo apt install -y wireguard wireguard-tools
Create the directory for keys and change into it:
sudo mkdir -p /etc/wireguard
sudo chmod 700 /etc/wireguard
cd /etc/wireguard
Generate the server’s key pair:
wg genkey | tee privatekey | wg pubkey > publickey
Set permissions and read the keys:
sudo chmod 600 privatekey publickey
sudo cat privatekey
sudo cat publickey
Note both values. The private key stays only on the server. Save the public key because you’ll need it for clients later.
Server Configuration
Create /etc/wireguard/wg0.conf with the following content. Replace placeholders with your actual private key, public domain or IP, and desired subnet.
[Interface]
PrivateKey = SERVER_PRIVATE_KEY
Address = 10.200.200.1/24
ListenPort = 51820
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = CLIENT_PUBLIC_KEY
AllowedIPs = 10.200.200.2/32
Replace SERVER_PRIVATE_KEY with the content of your privatekey file. Generate CLIENT_PUBLIC_KEY later on the client. Replace eth0 with your actual network interface, which might be ens18 or ens160. Check with ip link.
Enable IP forwarding:
echo "net.ipv4.ip_forward=1" | sudo tee -a /etc/sysctl.conf
sudo sysctl -p
Start the WireGuard tunnel:
sudo wg-quick up wg0
sudo systemctl enable wg-quick@wg0
Setting Up a Client
On your client device (laptop, tablet, or phone), generate your own key pair. On Linux, use the same command as before:
wg genkey | tee privatekey | wg pubkey > publickey
Back on the server, open the WireGuard configuration again and add a new [Peer] block for your client. Note down the IP address you assign to it, for example 10.200.200.2.
Your client configuration might look like this:
[Interface]
PrivateKey = CLIENT_PRIVATE_KEY
Address = 10.200.200.2/32
DNS = 1.1.1.1
[Peer]
PublicKey = SERVER_PUBLIC_KEY
AllowedIPs = 10.200.200.0/24, 192.168.1.0/24
Endpoint = meine-domain.de:51820
PersistentKeepalive = 25
Replace CLIENT_PRIVATE_KEY with the contents of your client’s privatekey file. SERVER_PUBLIC_KEY is your server’s public key. AllowedIPs determines which traffic flows through the tunnel. If you only want access to the VPN subnet and your home network, add both ranges. To route everything through the tunnel, use 0.0.0.0/0.
Accessing Ollama Over WireGuard
Once your client connects, you can reach Ollama using its internal IP address. If Ollama runs on a device in your home network at 192.168.1.42 on port 11434, simply access http://192.168.1.42:11434. You don’t need public DNS or a reverse proxy because the WireGuard tunnel places you directly on your home network.
If you want to route both DNS and all internet traffic through your server, set AllowedIPs to 0.0.0.0/0 and configure a DNS resolver on the server. For AI use cases alone, tunneling just the internal subnet usually suffices.
Common Pitfalls
-
Wrong network interface in PostUp/PostDown:
eth0isn’t always correct. Check your interface name withip link. -
IP forwarding disabled: Without this setting, the server won’t relay traffic to your home network.
-
Firewall blocks UDP 51820: The port must be open on the server and potentially your router.
-
Incorrect AllowedIPs: If only parts of your network are reachable, the issue usually lies in overly restrictive AllowedIPs settings.
-
Public keys mixed up: Server and client must each know the other’s public key. Swapped keys cause silent connection failures.
-
Missing PersistentKeepalive: Behind Carrier Grade NAT or certain routers, the connection drops without regular keepalive packets.
-
Dynamic DNS instead of a fixed IP: If your public IP changes, use a domain name. Your client won’t need manual updates, just a regular DNS refresh.
-
Private keys stored insecurely: Never share private keys via email or chat. If a device loses its key, remove that peer immediately.
-
MTU issues: Some networks require adjusted MTU values. The default is 1420; if you have problems, try 1380 or 1360.
-
Conflicts with other VPNs: Multiple active VPN connections can cause routing conflicts. Disable other VPNs during testing.
Hardware, Costs, and Security
WireGuard requires minimal resources. Even a Raspberry Pi 3 handles a handful of clients efficiently. If you’re running AI workloads on the same machine, you’ll need more RAM and CPU. For a pure VPN server, a budget VPS or older mini PC works fine.
Costs come mainly from hosting or electricity. A small cloud server typically costs two to five euros per month. A Raspberry Pi on your home network costs almost nothing in electricity, usually under one euro monthly. The software is open source and free.
WireGuard is cryptographically sound. Still, keep it updated, maintain strict firewall rules, and protect your keys. Open only UDP 51820 and close everything else you don’t need. Learn more in the Firewall section.
Further Reading
- Self-Hosting Overview
- Networking Basics
- Tailscale as an Alternative
- Ubuntu Server Basics
- Firewall Essentials
- Ollama Network Access
FAQ
-
Is WireGuard free?
Yes, it’s open source and completely free to use. -
Is WireGuard more secure than OpenVPN?
It uses modern cryptography and has far less source code, making it easier to audit. -
Do I need port forwarding for WireGuard?
Yes, if you’re running a home server. With a VPS that has a public IP, usually not. -
Can I use WireGuard on my smartphone?
Yes, official apps exist for both Android and iOS. -
Does WireGuard work behind Carrier Grade NAT?
Mostly yes.PersistentKeepalivehelps keep the connection alive. -
How many clients can one WireGuard server handle?
It depends on your hardware. With modest traffic, dozens work without issue. -
Does my server need to stay on all the time?
Yes, if you want constant access. -
Can I tunnel all my internet traffic?
Yes, setAllowedIPsto0.0.0.0/0and ensure MASQUERADE is configured correctly. -
What if my public IP changes?
Use a DynDNS system to keep your domain current. Your client usually adapts automatically. -
Is WireGuard suitable for AI services?
Yes, you access internal IPs as if they’re on your home network, without exposing services publicly. -
How do I remove a lost peer?
Delete the[Peer]block from the server configuration and restartwg-quick. -
Do I need to reconfigure my client each time it connects?
No, the configuration file is saved and can be quickly transferred to new devices via QR code or file.
Sources
- WireGuard official website: wireguard.com
- WireGuard Whitepaper by Jason A. Donenfeld
- Ubuntu Community Wiki: WireGuard
- Ollama official documentation: ollama.com
- IETF RFC on WireGuard and Noise Protocol Framework


