An interactive WireGuard server installer
A shell script that installs a WireGuard server, sets up forwarding and NAT, opens the firewall port and creates client configs with QR codes.
The toor11/scripts repository is a collection of system administration scripts. It had an openvpn-install.sh but nothing for WireGuard, and its dozen scripts had no index. My pull request added both: a README describing every script, and wireguard-install.sh, written in the same interactive style as the OpenVPN installer.
What the script does#
Run it as root:
sudo ./wireguard-install.sh
The first run asks a few questions, each with a default you can accept: the server’s public IP or hostname, the UDP port (51820), the public network interface, the tunnel subnet (10.66.66.0/24), the first client’s name and the DNS server to push to clients (1.1.1.1). Then it:
- Detects the distribution and installs WireGuard and
qrencodewith apt, dnf, yum or pacman. - Generates the server key pair and writes
/etc/wireguard/wg0.conf. - Turns on IPv4 forwarding in
/etc/sysctl.d/99-wireguard-forward.conf. - Adds NAT with iptables rules that come up and go down with the interface:
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
- Opens the UDP port in ufw or firewalld, whichever is active.
- Starts and enables
wg-quick@wg0. - Creates the first client: its own key pair plus a preshared key, a client config, and a QR code printed in the terminal for the WireGuard phone app.
Every later run shows a menu instead: add a client, revoke a client, or uninstall. Adding or revoking a client reloads the WireGuard interface so the change applies straight away.