The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Show all interfaces | sudo wg show | View examples |
| Show runtime configuration | sudo wg showconf wg0 | View examples |
| List WireGuard interfaces | wg show interfaces | View examples |
| Generate a private key | umask 077; wg genkey > privatekey | View examples |
| Derive a public key | wg pubkey < privatekey > publickey | View examples |
| Generate a preshared key | umask 077; wg genpsk > presharedkey | View examples |
| Create an interface | sudo ip link add dev wg0 type wireguard | View examples |
| Load configuration | sudo wg setconf wg0 /etc/wireguard/wg0.conf | View examples |
| Assign a tunnel address | sudo ip address add 10.20.0.1/24 dev wg0 | View examples |
| Bring the link up | sudo ip link set up dev wg0 | View examples |
| Start with wg-quick | sudo wg-quick up wg0 | View examples |
| Stop with wg-quick | sudo wg-quick down wg0 | View examples |
| Save runtime state | sudo wg-quick save wg0 | View examples |
| Synchronize peer config | sudo wg syncconf wg0 /run/wireguard/wg0.stripped.conf | View examples |
| Strip wg-quick fields | sudo wg-quick strip wg0 | View examples |
| Check route selection | ip route get 10.20.0.2 | View examples |
| Show handshake epochs | sudo wg show wg0 latest-handshakes | View examples |
| Show transfer counters | sudo wg show wg0 transfer | View examples |
| Show learned endpoints | sudo wg show wg0 endpoints | View examples |
| Update one peer | sudo wg set wg0 peer PUBLIC_KEY allowed-ips 10.20.0.2/32 \
endpoint vpn.example.net:51820 | View examples |
| Remove a peer | sudo wg set wg0 peer PUBLIC_KEY remove | View examples |
| Show tools version | wg --version | View examples |
WireGuard securely transports IP packets over UDP, but it does not distribute keys, addresses, DNS, routes, or authorization policy. Each peer public key identifies a cryptographic peer, while AllowedIPs acts as both an outbound routing selector and an inbound source-address allowlist. Keep private keys off terminals and repositories, plan firewall and return routing explicitly, and retain console access when changing a default route remotely.
Step by step
Detailed examples
Inspect runtime state without publishing secrets
wg show is operationally useful but reveals public keys, endpoints, transfer patterns, and network topology. wg showconf additionally exposes the interface private key and preshared keys, so never paste it into tickets or logs. Redact evidence and restrict sudo access.
wg --version
ip -brief link show type wireguard
sudo wg show wg0 public-key
sudo wg show wg0 peers
sudo wg show wg0 latest-handshakes
sudo wg show wg0 transfer Generate and store keys with strict permissions
A WireGuard private key authenticates the interface and cannot be recovered from its public key. Generate it in a protected directory under umask 077, avoid command substitution and terminal output, encrypt backups, and rotate on suspected disclosure. Preshared keys add a symmetric layer but create another shared secret to distribute safely.
# Run inside a root-owned mode-0700 directory, not a shared working tree.
# umask 077
# wg genkey > privatekey
# wg pubkey < privatekey > publickey
# wg genpsk > presharedkey
# stat -c '%a %U:%G %n' privatekey presharedkey Separate WireGuard configuration from ordinary IP configuration
wg configures cryptographic peers; ip configures addresses, routes, MTU, and link state. setconf ignores wg-quick-only keys such as Address, DNS, Table, and hooks. Build in a maintenance window, validate unique addresses and routes, and delete the interface during rollback only after preserving the management path.
# sudo ip link add dev wg0 type wireguard
# sudo wg setconf wg0 /etc/wireguard/wg0.conf
# sudo ip address add 10.20.0.1/24 dev wg0
# sudo ip link set mtu 1420 up dev wg0
# ip route get 10.20.0.2 Understand what wg-quick adds and removes
wg-quick infers addresses and routes and may invoke DNS tooling and arbitrary PreUp, PostUp, PreDown, or PostDown shell hooks as root. Treat configuration files as privileged code. A 0.0.0.0/0 or ::/0 AllowedIPs may replace default-route behavior using policy routing; remote administration needs an independent rollback path.
sudo wg-quick strip wg0
ip route show table all
ip rule show
# Disruptive lifecycle actions:
# sudo wg-quick up wg0
# sudo wg-quick down wg0 Design AllowedIPs as routing and authorization policy
For outbound traffic, WireGuard selects the peer whose AllowedIPs has the longest matching prefix. For inbound traffic it rejects decrypted packets whose source is not allowed for that peer. Overlapping prefixes can surprise operators; identical prefixes cannot safely represent multiple active peers on one interface. Include only intended networks and verify return routes and forwarding.
sudo wg show wg0 allowed-ips
ip route show table all
ip rule show
ip route get 10.20.0.2
ip -6 route get 2001:db8:20::2 Plan UDP reachability, forwarding, and NAT separately
WireGuard does not open firewall ports, enable IP forwarding, or add NAT by itself. A listening gateway needs an allowed UDP port and routed networks need explicit forward policy; NAT is only appropriate when real return routing is unavailable. PersistentKeepalive is generally needed only for a peer behind NAT that must receive after idle time; 25 seconds is a common value, not a universal requirement.
sudo wg show wg0 listen-port
sudo wg show wg0 endpoints
sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding
sudo nft list ruleset
ss -lunp Reload peers without discarding established state
wg setconf replaces peer configuration, whereas syncconf changes only differences and is less disruptive. wg-quick strip converts a wg-quick file to wg syntax, but both outputs can contain secrets. Generate temporary material in a root-only runtime directory, validate it, apply it, and securely remove it according to local policy.
# Root-only runtime directory and files are required.
# sudo wg-quick strip wg0 > /run/wireguard/wg0.stripped.conf
# sudo wg syncconf wg0 /run/wireguard/wg0.stripped.conf
# sudo wg show wg0 Rotate and revoke peers in both live and persistent state
A live wg set is lost when the interface is rebuilt unless persistent configuration is also changed. For rotation, provision the new peer identity, constrain AllowedIPs, verify handshakes and application paths, then revoke the old public key. Never reuse one private key across hosts because identity and revocation become inseparable.
sudo wg show wg0 peers
sudo wg show wg0 allowed-ips
sudo wg show wg0 latest-handshakes
# After persistent configuration is prepared:
# sudo wg set wg0 peer PUBLIC_KEY remove Read handshake, counters, routes, and MTU together
A recent handshake proves cryptographic contact, not application reachability. No handshake points toward keys, endpoints, UDP filtering, DNS, or clocks; handshakes with no useful traffic suggest AllowedIPs, routes, forwarding, firewall, or MTU. Capture tcpdump only with authorization because payloads inside the tunnel and endpoint metadata may be sensitive.
wg --version
sudo wg show wg0
ip -details link show wg0
ip address show dev wg0
ip route show table all
ip rule show
journalctl -k --since '-10 minutes' --no-pager Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- WireGuard ProjectWireGuard Quick Startwireguard.com
- WireGuard ProjectWireGuard Conceptual Overviewwireguard.com
- WireGuard Projectwg(8) Manualgit.zx2c4.com
- WireGuard Projectwg-quick(8) Manualgit.zx2c4.com
- WireGuard ProjectWireGuard Protocol and Cryptographywireguard.com
- WireGuard ProjectWireGuard Whitepaperwireguard.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



