Guides ยท Sep 27, 2026
How to Set Up Your Own WireGuard VPN on a VPS
Set up a personal WireGuard VPN server on an Ubuntu or Debian VPS in about 10 minutes, then connect your phone and laptop.
WireGuard is a fast, modern VPN that's built into the Linux kernel. Running it on your own VPS gives you a private IP address that nobody else shares. Even our smallest plan handles a personal or family VPN easily.
1. Install WireGuard
sudo apt update
sudo apt install -y wireguard qrencode
2. Create server and client keys
cd /etc/wireguard
umask 077
wg genkey | tee server.key | wg pubkey > server.pub
wg genkey | tee phone.key | wg pubkey > phone.pub
3. Create the server config
Find your network interface name with ip route | grep default (often eth0 or ens3), then create /etc/wireguard/wg0.conf:
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = (contents of server.key)
PostUp = iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = (contents of phone.pub)
AllowedIPs = 10.8.0.2/32
4. Enable forwarding and start it
echo "net.ipv4.ip_forward=1" | sudo tee /etc/sysctl.d/99-wireguard.conf
sudo sysctl --system
sudo ufw allow 51820/udp
sudo systemctl enable --now wg-quick@wg0
5. Connect your phone
Create phone.conf:
[Interface]
PrivateKey = (contents of phone.key)
Address = 10.8.0.2/32
DNS = 1.1.1.1
[Peer]
PublicKey = (contents of server.pub)
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25
Show it as a QR code and scan it with the WireGuard app:
qrencode -t ansiutf8 < phone.conf
Keep it personal
A VPN for yourself, your family or your team is welcome. Reselling VPN access or using it to hide abuse breaks our Acceptable Use Rules.
Need a server for this?
Every TidalVPS VPS comes with full root access, unmetered traffic, daily backups and DDoS protection.