How to Set Up WireGuard VPN
Self-host a fast, modern WireGuard VPN so you can reach your entire homelab securely from anywhere — with wg-easy for a simple UI.
Why WireGuard
The safest way to reach your home server from outside is not to expose each service to the internet, but to connect into your network through a VPN. WireGuard is the modern choice: it's extremely fast, uses state-of-the-art cryptography, and has tiny, readable configs. Once connected, you use your services exactly as if you were at home.
This tutorial uses wg-easy, a container that gives WireGuard a simple web UI and QR codes for clients.
Prerequisites
- A server reachable from the internet — either a public IP with port forwarding, or a small cloud VPS as an entry point.
- A dynamic DNS hostname if your home IP changes (see Dynamic DNS).
- Docker.
Step 1: Forward the WireGuard port
On your router, forward UDP port 51820 to your server. WireGuard uses UDP only — there's nothing to see if someone port-scans it, which is part of its appeal.
Step 2: Deploy wg-easy
services:
wg-easy:
image: ghcr.io/wg-easy/wg-easy:latest
container_name: wg-easy
restart: unless-stopped
environment:
- WG_HOST=vpn.example.com # your public hostname or IP
- PASSWORD_HASH=REPLACE_ME # bcrypt hash for the web UI
- WG_DEFAULT_DNS=192.168.1.10 # your Pi-hole/AdGuard, optional
ports:
- "51820:51820/udp"
- "51821:tcp" # web UI (keep internal)
volumes:
- ./config:/etc/wireguard
cap_add:
- NET_ADMIN
- SYS_MODULE
sysctls:
- net.ipv4.ip_forward=1Set WG_HOST to how clients reach you, and generate a bcrypt hash for PASSWORD_HASH. Start it:
docker compose up -dStep 3: Create clients
Open the web UI at http://your-server-ip:51821 (keep this port internal — don't forward it). Create a client for each device. wg-easy shows a QR code:
- Phone: install the WireGuard app and scan the QR code.
- Laptop: download the config file and import it into the WireGuard client.
Step 4: Choose split vs. full tunnel
Each client's AllowedIPs decides what goes through the VPN:
- Split tunnel (
AllowedIPs = 192.168.1.0/24) — only home-network traffic uses the VPN; your normal browsing goes out directly. Best for everyday remote access. - Full tunnel (
AllowedIPs = 0.0.0.0/0) — all traffic routes through home. Useful on untrusted Wi-Fi and to use your Pi-hole everywhere.
Step 5: Test it
Turn off Wi-Fi on your phone (use mobile data), enable the WireGuard tunnel, and try reaching an internal service by its LAN IP or internal hostname. If it loads, you're done — your homelab is now reachable securely from anywhere.
WireGuard vs. Tailscale
wg-easy is self-hosted WireGuard with full control. If you want automatic NAT traversal without port forwarding and near-zero setup, Tailscale (which is built on WireGuard) is worth considering — see Tailscale vs WireGuard.
Security notes
- Keep the wg-easy web UI off the internet — only 51820/udp should be forwarded.
- Give each device its own client config so you can revoke one without disrupting others.
- Consider routing clients' DNS through your Pi-hole for ad-blocking on the go.
Troubleshooting
- Handshake but no traffic — check
AllowedIPsand that IP forwarding is enabled. - No handshake at all — the UDP port isn't forwarded, or
WG_HOSTis wrong. - Works on Wi-Fi, not mobile — confirm the public hostname/IP resolves from outside your network.
Next steps
With a VPN in place, you can safely keep dashboards like Portainer and Proxmox internal-only, exposing nothing to the public internet.
Verwandte Artikel
How to Install Nginx Proxy Manager
Publish internal services with free Let's Encrypt TLS certificates and a friendly point-and-click UI — no config files required.
How to Set Up Caddy as a Reverse Proxy
Get automatic HTTPS for all your homelab services with Caddy's tiny config — including Docker, subdomains and DNS challenges.
Secure Remote Access to Your Home Server
Reach your homelab from anywhere without exposing insecure ports — compare VPNs, Tailscale, reverse proxies and tunnels, and when to use each.