The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show all interfacessudo wg showView examples
Show runtime configurationsudo wg showconf wg0View examples
List WireGuard interfaceswg show interfacesView examples
Generate a private keyumask 077; wg genkey > privatekeyView examples
Derive a public keywg pubkey < privatekey > publickeyView examples
Generate a preshared keyumask 077; wg genpsk > presharedkeyView examples
Create an interfacesudo ip link add dev wg0 type wireguardView examples
Load configurationsudo wg setconf wg0 /etc/wireguard/wg0.confView examples
Assign a tunnel addresssudo ip address add 10.20.0.1/24 dev wg0View examples
Bring the link upsudo ip link set up dev wg0View examples
Start with wg-quicksudo wg-quick up wg0View examples
Stop with wg-quicksudo wg-quick down wg0View examples
Save runtime statesudo wg-quick save wg0View examples
Synchronize peer configsudo wg syncconf wg0 /run/wireguard/wg0.stripped.confView examples
Strip wg-quick fieldssudo wg-quick strip wg0View examples
Check route selectionip route get 10.20.0.2View examples
Show handshake epochssudo wg show wg0 latest-handshakesView examples
Show transfer counterssudo wg show wg0 transferView examples
Show learned endpointssudo wg show wg0 endpointsView examples
Update one peersudo wg set wg0 peer PUBLIC_KEY allowed-ips 10.20.0.2/32 \ endpoint vpn.example.net:51820View examples
Remove a peersudo wg set wg0 peer PUBLIC_KEY removeView examples
Show tools versionwg --versionView examples

WireGuard securely transports IP packets over UDP, but it does not distribute keys, addresses, DNS, routes, or authorization policy. Each peer public key identifies a cryptographic peer, while AllowedIPs acts as both an outbound routing selector and an inbound source-address allowlist. Keep private keys off terminals and repositories, plan firewall and return routing explicitly, and retain console access when changing a default route remotely.

Step by step

Detailed examples

01

Inspect runtime state without publishing secrets

wg show is operationally useful but reveals public keys, endpoints, transfer patterns, and network topology. wg showconf additionally exposes the interface private key and preshared keys, so never paste it into tickets or logs. Redact evidence and restrict sudo access.

Collect a minimally sensitive baseline
wg --version
ip -brief link show type wireguard
sudo wg show wg0 public-key
sudo wg show wg0 peers
sudo wg show wg0 latest-handshakes
sudo wg show wg0 transfer
Back to quick reference ↑
02

Generate and store keys with strict permissions

A WireGuard private key authenticates the interface and cannot be recovered from its public key. Generate it in a protected directory under umask 077, avoid command substitution and terminal output, encrypt backups, and rotate on suspected disclosure. Preshared keys add a symmetric layer but create another shared secret to distribute safely.

Document a protected key-generation workflow
# Run inside a root-owned mode-0700 directory, not a shared working tree.
# umask 077
# wg genkey > privatekey
# wg pubkey < privatekey > publickey
# wg genpsk > presharedkey
# stat -c '%a %U:%G %n' privatekey presharedkey
Back to quick reference ↑
03

Separate WireGuard configuration from ordinary IP configuration

wg configures cryptographic peers; ip configures addresses, routes, MTU, and link state. setconf ignores wg-quick-only keys such as Address, DNS, Table, and hooks. Build in a maintenance window, validate unique addresses and routes, and delete the interface during rollback only after preserving the management path.

Review a manual bring-up sequence
# sudo ip link add dev wg0 type wireguard
# sudo wg setconf wg0 /etc/wireguard/wg0.conf
# sudo ip address add 10.20.0.1/24 dev wg0
# sudo ip link set mtu 1420 up dev wg0
# ip route get 10.20.0.2
Back to quick reference ↑
04

Understand what wg-quick adds and removes

wg-quick infers addresses and routes and may invoke DNS tooling and arbitrary PreUp, PostUp, PreDown, or PostDown shell hooks as root. Treat configuration files as privileged code. A 0.0.0.0/0 or ::/0 AllowedIPs may replace default-route behavior using policy routing; remote administration needs an independent rollback path.

Inspect before lifecycle operations
sudo wg-quick strip wg0
ip route show table all
ip rule show
# Disruptive lifecycle actions:
# sudo wg-quick up wg0
# sudo wg-quick down wg0
Back to quick reference ↑
05

Design AllowedIPs as routing and authorization policy

For outbound traffic, WireGuard selects the peer whose AllowedIPs has the longest matching prefix. For inbound traffic it rejects decrypted packets whose source is not allowed for that peer. Overlapping prefixes can surprise operators; identical prefixes cannot safely represent multiple active peers on one interface. Include only intended networks and verify return routes and forwarding.

Audit route and peer selection
sudo wg show wg0 allowed-ips
ip route show table all
ip rule show
ip route get 10.20.0.2
ip -6 route get 2001:db8:20::2
Back to quick reference ↑
06

Plan UDP reachability, forwarding, and NAT separately

WireGuard does not open firewall ports, enable IP forwarding, or add NAT by itself. A listening gateway needs an allowed UDP port and routed networks need explicit forward policy; NAT is only appropriate when real return routing is unavailable. PersistentKeepalive is generally needed only for a peer behind NAT that must receive after idle time; 25 seconds is a common value, not a universal requirement.

Inspect reachability prerequisites
sudo wg show wg0 listen-port
sudo wg show wg0 endpoints
sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding
sudo nft list ruleset
ss -lunp
Back to quick reference ↑
07

Reload peers without discarding established state

wg setconf replaces peer configuration, whereas syncconf changes only differences and is less disruptive. wg-quick strip converts a wg-quick file to wg syntax, but both outputs can contain secrets. Generate temporary material in a root-only runtime directory, validate it, apply it, and securely remove it according to local policy.

Review a low-disruption reload pattern
# Root-only runtime directory and files are required.
# sudo wg-quick strip wg0 > /run/wireguard/wg0.stripped.conf
# sudo wg syncconf wg0 /run/wireguard/wg0.stripped.conf
# sudo wg show wg0
Back to quick reference ↑
08

Rotate and revoke peers in both live and persistent state

A live wg set is lost when the interface is rebuilt unless persistent configuration is also changed. For rotation, provision the new peer identity, constrain AllowedIPs, verify handshakes and application paths, then revoke the old public key. Never reuse one private key across hosts because identity and revocation become inseparable.

Audit before revocation
sudo wg show wg0 peers
sudo wg show wg0 allowed-ips
sudo wg show wg0 latest-handshakes
# After persistent configuration is prepared:
# sudo wg set wg0 peer PUBLIC_KEY remove
Back to quick reference ↑
09

Read handshake, counters, routes, and MTU together

A recent handshake proves cryptographic contact, not application reachability. No handshake points toward keys, endpoints, UDP filtering, DNS, or clocks; handshakes with no useful traffic suggest AllowedIPs, routes, forwarding, firewall, or MTU. Capture tcpdump only with authorization because payloads inside the tunnel and endpoint metadata may be sensitive.

Gather bounded diagnostics
wg --version
sudo wg show wg0
ip -details link show wg0
ip address show dev wg0
ip route show table all
ip rule show
journalctl -k --since '-10 minutes' --no-pager
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. WireGuard ProjectWireGuard Quick Startwireguard.com
  2. WireGuard ProjectWireGuard Conceptual Overviewwireguard.com
  3. WireGuard Projectwg(8) Manualgit.zx2c4.com
  4. WireGuard Projectwg-quick(8) Manualgit.zx2c4.com
  5. WireGuard ProjectWireGuard Protocol and Cryptographywireguard.com
  6. WireGuard ProjectWireGuard Whitepaperwireguard.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback