cenko.tech

An interactive WireGuard server installer

A shell script that installs a WireGuard server, sets up forwarding and NAT, opens the firewall port and creates client configs with QR codes.

The toor11/scripts repository is a collection of system administration scripts. It had an openvpn-install.sh but nothing for WireGuard, and its dozen scripts had no index. My pull request added both: a README describing every script, and wireguard-install.sh, written in the same interactive style as the OpenVPN installer.

What the script does#

Run it as root:

sudo ./wireguard-install.sh

The first run asks a few questions, each with a default you can accept: the server’s public IP or hostname, the UDP port (51820), the public network interface, the tunnel subnet (10.66.66.0/24), the first client’s name and the DNS server to push to clients (1.1.1.1). Then it:

  1. Detects the distribution and installs WireGuard and qrencode with apt, dnf, yum or pacman.
  2. Generates the server key pair and writes /etc/wireguard/wg0.conf.
  3. Turns on IPv4 forwarding in /etc/sysctl.d/99-wireguard-forward.conf.
  4. Adds NAT with iptables rules that come up and go down with the interface:
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
  1. Opens the UDP port in ufw or firewalld, whichever is active.
  2. Starts and enables wg-quick@wg0.
  3. Creates the first client: its own key pair plus a preshared key, a client config, and a QR code printed in the terminal for the WireGuard phone app.

Every later run shows a menu instead: add a client, revoke a client, or uninstall. Adding or revoking a client reloads the WireGuard interface so the change applies straight away.

cd ~/blog