Setting Up a WireGuard VPN on a Raspberry Pi for Remote Access

A Raspberry Pi can provide a compact, quiet and inexpensive gateway into a home network. With WireGuard, you can connect securely to files, dashboards, cameras and other services while travelling, without exposing every internal device directly to the internet. The setup is well suited to an Australian home office, shed, small business or homelab.

The project involves more than installing a VPN package. You need to account for your internet provider, router configuration, dynamic public addresses, firewall rules and the security of each client device. A careful design will make the tunnel reliable on an NBN connection in Brisbane, Melbourne or regional New South Wales, even when the public IP address changes.

Choose The Raspberry Pi And Network Design

A Raspberry Pi 4 or Pi 5 with at least 2 GB of memory is more than capable of handling WireGuard for a household or small remote-access deployment. A Pi 3 can also work, particularly for a few mobile clients. Use a reliable USB-C power supply, a quality microSD card and an Ethernet connection rather than Wi-Fi wherever possible. Jaycar and similar Australian electronics retailers often stock suitable cases, power supplies and network accessories.

Install Raspberry Pi OS Lite 64-bit if the device will run as a dedicated appliance. Give it a fixed address on the local network, either by configuring a DHCP reservation in the router or by assigning a static address in the operating system. A reserved address such as 192.168.1.20 makes port forwarding and troubleshooting much easier.

WireGuard creates a private tunnel between peers using public-key cryptography. The Pi acts as the server, while a laptop, phone or tablet becomes a client. You can route only traffic destined for the home network, or send all client traffic through the Pi. The split-tunnel option is usually preferable for remote access because it avoids unnecessary load and preserves normal local internet performance.

When travelling, a private tunnel can protect access to personal services and make browsing behave consistently across unfamiliar networks, whether you are checking a home dashboard or reading live blackjack play from hotel Wi-Fi. The important point is that the VPN protects the connection between the client and home network; it does not make an untrusted website safe.

Install WireGuard And Generate Keys

Update the Pi before installing the VPN software:

sudo apt update
sudo apt full-upgrade -y
sudo apt install wireguard qrencode

WireGuard uses a private key and public key for every peer. Keep the server private key on the Raspberry Pi and never paste it into a ticket, chat message or public repository. Generate the server keys with:

sudo umask 077
wg genkey | sudo tee /etc/wireguard/server.key | wg pubkey | sudo tee /etc/wireguard/server.pub

Create a key pair for each client. A phone, work laptop and personal desktop should have separate identities, so one lost device can be revoked without replacing every configuration:

wg genkey | tee client-phone.key | wg pubkey > client-phone.pub

The server configuration belongs in /etc/wireguard/wg0.conf. A basic example looks like this:

[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT

[Peer]
PublicKey = CLIENT_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32

Replace the placeholder values with the contents of the appropriate key files. Avoid copying a private key into shell history or a shared document. The AllowedIPs value identifies the address assigned to this particular client and prevents accidental overlap.

Configure Routing And Port Forwarding

Enable IPv4 forwarding so the Pi can pass traffic between the VPN interface and the home LAN:

echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/99-wireguard.conf
sudo sysctl --system

If clients need to reach devices on the LAN, add a route or NAT rule according to your network design. NAT is convenient when the home router does not know how to return traffic to the WireGuard subnet:

sudo iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE

For a persistent production setup, save firewall rules with a suitable package such as iptables-persistent, or implement equivalent rules in your existing firewall. Check that the interface name is actually eth0; some installations use a different name.

Forward UDP port 51820 from the home router to the Pi’s LAN address. WireGuard does not use TCP, so forwarding the wrong protocol will produce a silent failure. Australian NBN providers vary in how they handle inbound connections. Some services provide a public IPv4 address, while others place customers behind carrier-grade NAT. If your router’s WAN address differs from the address shown by an external check, inbound IPv4 port forwarding may not work.

Contact the provider or examine IPv6 support if CGNAT is involved. A public static address is useful for business connections, but a dynamic DNS hostname is usually enough for residential access. DuckDNS, Cloudflare DNS and provider-specific services can update a hostname whenever the NBN address changes.

Build A Client Profile And Test Access

A client configuration needs the client private key, its tunnel address, the server public key and an endpoint hostname:

[Interface]
PrivateKey = CLIENT_PRIVATE_KEY
Address = 10.8.0.2/32
DNS = 192.168.1.1

[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = vpn.example.net:51820
AllowedIPs = 192.168.1.0/24
PersistentKeepalive = 25

The AllowedIPs line shown here creates a split tunnel for the home LAN. Use 0.0.0.0/0, ::/0 only when all client traffic should pass through home. PersistentKeepalive = 25 is useful for phones and laptops behind restrictive hotel, café or mobile networks. It sends a small packet often enough to keep NAT mappings open.

On Android or iOS, import the profile by scanning a QR code generated on the Pi:

qrencode -t ansiutf8 < client-phone.conf

Be cautious when displaying the QR code in a shared room because it contains the client’s private key. After activating the tunnel, test the Pi’s VPN address, then a known LAN service such as a file server or home assistant instance. sudo wg show displays the latest handshake and transfer counters.

A handshake confirms that the peers can communicate, but it does not prove that routing works. Test name resolution, access to the intended subnet and any firewall restrictions separately. If the tunnel works from mobile data but not from your home Wi-Fi, the issue may be router loopback or hairpin NAT rather than WireGuard itself.

Harden And Maintain The VPN

Use long, unique keys and one peer per device. Remove a lost phone or retired laptop from the server configuration promptly. Keep the Raspberry Pi patched, disable password-based SSH where practical, and use a firewall that permits SSH only from trusted addresses or through the VPN. The VPN should be an additional protected entry point, not a reason to leave other administration interfaces exposed.

Limit the services reachable through the tunnel. If remote users need access to a monitoring dashboard, there is no reason to permit unrestricted access to every management port. Review firewall rules and peer entries periodically, especially in a small consulting environment where equipment may be replaced frequently.

Back up /etc/wireguard, the firewall configuration and the dynamic DNS settings securely. Do not place private keys in an unencrypted cloud folder. A simple encrypted backup stored separately from the Pi can save considerable time after a failed microSD card or a power event.

Monitoring matters as well. Record the last handshake, check disk health and watch for repeated authentication or port scans. Karl Katzke’s technology blog provides a useful context for treating a small home appliance with the same operational discipline applied to larger infrastructure. For organising configuration notes, device inventories and renewal dates, a simple project checklist can prevent small administrative tasks from being forgotten.

Set up the Pi, verify the tunnel from outside the house and document the recovery steps while everything is working. A clearly labelled client profile, a tested backup and a short record of router settings will make remote access dependable when you are away from home, whether you are in Perth, Cairns or a regional town.

Experience

Information Technology Consulting

Independent Practice

Provides IT consulting services focused on infrastructure planning, cloud migration strategy, and systems architecture. Engagements draw on years of hands-on sysadmin and development experience across Linux, Windows, and hybrid environments.

K9 Search & Rescue Volunteer

Ongoing

Active participant in K9 Search & Rescue operations, combining technical logistics skills with field support for canine search teams.

Karl Katzke's Blog

October 2006 – May 2014

Published a long-running personal technology blog covering cloud vs. in-house infrastructure, F# and Mono on OSX, hardware vendor critiques, RAID card performance analysis, and sysadmin storytelling. Notable posts include "When Sysadmins Ruled the Earth" (May 15, 2014) and "Getting Started with F# and Mono on OSX" (December 22, 2012).

Credentials

A small badge icon with a shield shape in muted blue tones on a light background

Systems Administration

Deep experience with Linux (RHEL, SLES, CentOS), high-availability clusters, and STONITH configurations.

A small badge icon with a gear shape in muted blue tones on a light background

Cloud Infrastructure

Practical knowledge of AWS EC2, reserved instances, and cost analysis for cloud vs. on-premises deployments.

A small badge icon with a code symbol in muted blue tones on a light background

Development

Proficient in F#, PHP (Symfony), and cross-platform tooling including Mono and MonoDevelop on OSX.

Studies

F# & Functional Programming

Self-directed, 2012

Explored strongly typed functional programming with F# on OSX using the Mono runtime. Published a detailed getting-started guide covering toolchain setup and cross-platform game development research.

High-Availability & Cluster Management

Professional Development, 2009

Configured and documented crm_mon email alerting for STONITH events on SLES11-HAE clusters, integrating with Nagios monitoring for production environments.

Hardware & Storage Performance

Ongoing

Conducted hands-on benchmarking of SATA/SAS RAID controllers including HighPoint RocketRaid 2740 and LSI/SuperMicro AOC-USASLP2-H8iR, comparing against software RAID configurations.

Skills

A small icon representing a server with clean geometric lines in slate blue

Linux Administration

RHEL, SLES, CentOS — package management, kernel tuning, HA clustering, and monitoring integration.

A small icon representing a cloud shape with clean geometric lines in slate blue

Cloud Architecture

AWS EC2, reserved-instance planning, cost modeling, and hybrid infrastructure strategy.

A small icon representing code brackets with clean geometric lines in slate blue

F# & .NET/Mono

Functional programming on OSX, MonoDevelop toolchain, and cross-platform game-dev exploration.

A small icon representing a database cylinder with clean geometric lines in slate blue

PHP & Symfony

Web application development with the Symfony framework and the broader PHP ecosystem.

A small icon representing a storage drive with clean geometric lines in slate blue

Storage & RAID

SATA/SAS controller evaluation, md RAID configuration, and performance benchmarking.

A small icon representing a shield with clean geometric lines in slate blue

High Availability

Pacemaker, STONITH, crm_mon alerting, and Nagios integration for production cluster monitoring.