Setting Up a WireGuard VPN on a Raspberry Pi for Remote Access
A Raspberry Pi can provide a compact, quiet and inexpensive gateway into a home network. With WireGuard, you can connect securely to files, dashboards, cameras and other services while travelling, without exposing every internal device directly to the internet. The setup is well suited to an Australian home office, shed, small business or homelab.
The project involves more than installing a VPN package. You need to account for your internet provider, router configuration, dynamic public addresses, firewall rules and the security of each client device. A careful design will make the tunnel reliable on an NBN connection in Brisbane, Melbourne or regional New South Wales, even when the public IP address changes.
Choose The Raspberry Pi And Network Design
A Raspberry Pi 4 or Pi 5 with at least 2 GB of memory is more than capable of handling WireGuard for a household or small remote-access deployment. A Pi 3 can also work, particularly for a few mobile clients. Use a reliable USB-C power supply, a quality microSD card and an Ethernet connection rather than Wi-Fi wherever possible. Jaycar and similar Australian electronics retailers often stock suitable cases, power supplies and network accessories.
Install Raspberry Pi OS Lite 64-bit if the device will run as a dedicated appliance. Give it a fixed address on the local network, either by configuring a DHCP reservation in the router or by assigning a static address in the operating system. A reserved address such as 192.168.1.20 makes port forwarding and troubleshooting much easier.
WireGuard creates a private tunnel between peers using public-key cryptography. The Pi acts as the server, while a laptop, phone or tablet becomes a client. You can route only traffic destined for the home network, or send all client traffic through the Pi. The split-tunnel option is usually preferable for remote access because it avoids unnecessary load and preserves normal local internet performance.
When travelling, a private tunnel can protect access to personal services and make browsing behave consistently across unfamiliar networks, whether you are checking a home dashboard or reading live blackjack play from hotel Wi-Fi. The important point is that the VPN protects the connection between the client and home network; it does not make an untrusted website safe.
Install WireGuard And Generate Keys
Update the Pi before installing the VPN software:
sudo apt update
sudo apt full-upgrade -y
sudo apt install wireguard qrencode
WireGuard uses a private key and public key for every peer. Keep the server private key on the Raspberry Pi and never paste it into a ticket, chat message or public repository. Generate the server keys with:
sudo umask 077
wg genkey | sudo tee /etc/wireguard/server.key | wg pubkey | sudo tee /etc/wireguard/server.pub
Create a key pair for each client. A phone, work laptop and personal desktop should have separate identities, so one lost device can be revoked without replacing every configuration:
wg genkey | tee client-phone.key | wg pubkey > client-phone.pub
The server configuration belongs in /etc/wireguard/wg0.conf. A basic example looks like this:
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT
[Peer]
PublicKey = CLIENT_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32
Replace the placeholder values with the contents of the appropriate key files. Avoid copying a private key into shell history or a shared document. The AllowedIPs value identifies the address assigned to this particular client and prevents accidental overlap.
Configure Routing And Port Forwarding
Enable IPv4 forwarding so the Pi can pass traffic between the VPN interface and the home LAN:
echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/99-wireguard.conf
sudo sysctl --system
If clients need to reach devices on the LAN, add a route or NAT rule according to your network design. NAT is convenient when the home router does not know how to return traffic to the WireGuard subnet:
sudo iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
For a persistent production setup, save firewall rules with a suitable package such as iptables-persistent, or implement equivalent rules in your existing firewall. Check that the interface name is actually eth0; some installations use a different name.
Forward UDP port 51820 from the home router to the Pi’s LAN address. WireGuard does not use TCP, so forwarding the wrong protocol will produce a silent failure. Australian NBN providers vary in how they handle inbound connections. Some services provide a public IPv4 address, while others place customers behind carrier-grade NAT. If your router’s WAN address differs from the address shown by an external check, inbound IPv4 port forwarding may not work.
Contact the provider or examine IPv6 support if CGNAT is involved. A public static address is useful for business connections, but a dynamic DNS hostname is usually enough for residential access. DuckDNS, Cloudflare DNS and provider-specific services can update a hostname whenever the NBN address changes.
Build A Client Profile And Test Access
A client configuration needs the client private key, its tunnel address, the server public key and an endpoint hostname:
[Interface]
PrivateKey = CLIENT_PRIVATE_KEY
Address = 10.8.0.2/32
DNS = 192.168.1.1
[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = vpn.example.net:51820
AllowedIPs = 192.168.1.0/24
PersistentKeepalive = 25
The AllowedIPs line shown here creates a split tunnel for the home LAN. Use 0.0.0.0/0, ::/0 only when all client traffic should pass through home. PersistentKeepalive = 25 is useful for phones and laptops behind restrictive hotel, café or mobile networks. It sends a small packet often enough to keep NAT mappings open.
On Android or iOS, import the profile by scanning a QR code generated on the Pi:
qrencode -t ansiutf8 < client-phone.conf
Be cautious when displaying the QR code in a shared room because it contains the client’s private key. After activating the tunnel, test the Pi’s VPN address, then a known LAN service such as a file server or home assistant instance. sudo wg show displays the latest handshake and transfer counters.
A handshake confirms that the peers can communicate, but it does not prove that routing works. Test name resolution, access to the intended subnet and any firewall restrictions separately. If the tunnel works from mobile data but not from your home Wi-Fi, the issue may be router loopback or hairpin NAT rather than WireGuard itself.
Harden And Maintain The VPN
Use long, unique keys and one peer per device. Remove a lost phone or retired laptop from the server configuration promptly. Keep the Raspberry Pi patched, disable password-based SSH where practical, and use a firewall that permits SSH only from trusted addresses or through the VPN. The VPN should be an additional protected entry point, not a reason to leave other administration interfaces exposed.
Limit the services reachable through the tunnel. If remote users need access to a monitoring dashboard, there is no reason to permit unrestricted access to every management port. Review firewall rules and peer entries periodically, especially in a small consulting environment where equipment may be replaced frequently.
Back up /etc/wireguard, the firewall configuration and the dynamic DNS settings securely. Do not place private keys in an unencrypted cloud folder. A simple encrypted backup stored separately from the Pi can save considerable time after a failed microSD card or a power event.
Monitoring matters as well. Record the last handshake, check disk health and watch for repeated authentication or port scans. Karl Katzke’s technology blog provides a useful context for treating a small home appliance with the same operational discipline applied to larger infrastructure. For organising configuration notes, device inventories and renewal dates, a simple project checklist can prevent small administrative tasks from being forgotten.
Set up the Pi, verify the tunnel from outside the house and document the recovery steps while everything is working. A clearly labelled client profile, a tested backup and a short record of router settings will make remote access dependable when you are away from home, whether you are in Perth, Cairns or a regional town.
Karl Katzke