WireGuard

WireGuard

Network & Security · Version 1.0.20210914 · Debian 13

Your Seed is up within seconds and sets up WireGuard on its first boot. A few minutes later the app is ready to use.

WireGuard turns your Seed into a private VPN server. Laptops and phones connect through the official WireGuard apps for Windows, macOS, iOS and Android, and you add a device by scanning a QR code or importing a configuration file. On hotel or public Wi-Fi, your traffic then travels encrypted to the Seed and on to the internet from there. Services that only accept allowlisted IP addresses always see the address of your Seed. You can connect servers and other Seeds the same way and reach their internal services through the tunnel. The installation creates access for your first device right away.

After the first boot

The VPN server is ready 1 to 2 minutes after the Seed is created. /root/ready.txt then shows the server's address and port, and by that point the tunnel has already passed a connection test. If something goes wrong, the setup writes /root/failed.txt with the reason instead, and the full log is in /root/wireguard-install.log. Until one of the two files appears, setup is still running. You can reach both files via SSH or the Seed's VNC console.

The access files for your devices are in /root/wireguard-clients/, one configuration per device (client1.conf, client2.conf and so on, as many as set in WG_CLIENTS), each with a QR code as a PNG. Every file contains a private key and belongs on exactly one device.

  • On a phone, open the WireGuard app and scan the QR code that qrencode -t ansiutf8 < /root/wireguard-clients/client1.conf prints in the terminal.
  • On a laptop, copy the file with scp and import it into the WireGuard app.
  • On a Linux server, install the tools with apt install wireguard-tools, save the file as /etc/wireguard/wg0.conf and remove the DNS line so the server keeps its own resolvers. Set AllowedIPs to 10.0.0.0/24 plus the IPv6 prefix from the Address line with /64, for example 10.0.0.0/24, fd12:3456:789a::/64, so SSH keeps using the server's public address. Then start the tunnel with systemctl enable --now wg-quick@wg0.

With the unchanged configuration, laptops and phones send all their traffic through the tunnel.

Devices connect to the Seed's public IPv4 address. If you use a firewall under Network > Firewalls, it has to allow UDP port 51820 or the port from WG_PORT. The tunnel runs as the wg-quick@wg0 service, with its configuration in /etc/wireguard/wg0.conf. Its rules forward only traffic that comes from the tunnel and drop new connections from outside to your devices. wg show wg0 allowed-ips lists the tunnel addresses in use, and our guide Set up a WireGuard VPN server shows how to add more devices with the next free address.

Suitable models

Recommended

Entry

The entry point for low CPU load


Shared vCPUs
Xeon Gold class CPU
DDR4 ECC RAM
For low CPU load
3-way replication via Ceph
10 TB traffic included
Up to 1 Gbit/s connectivity

from
3,65 €
/ Month
from
0,005848 €
/ Hour

Standard

All-rounder for variable production load


Shared vCPUs
AMD EPYC 9655 (Turin)
DDR5 ECC RAM
For variable production load
3-way replication via Ceph
20 TB traffic included
Up to 2.5 Gbit/s connectivity

from
8,93 €
/ Month
from
0,014303 €
/ Hour

Performance

Exclusive compute for sustained load


Dedicated vCPUs
AMD EPYC 9575F (Turin)
DDR5 ECC RAM
For sustained load
3-way replication via Ceph
20 TB traffic included
Up to 10 Gbit/s connectivity

from
44,03 €
/ Month
from
0,070561 €
/ Hour

All prices incl. 19% VAT

Show all 15 suitable models

Entry

ModelCPU RAM StorageTraffic BandwidthPrice/hourPrice/month
S1 Core2 GB20 GB10 TB1 Gbit/s
0,005848 €
3,65 €
M2 Cores4 GB40 GB10 TB1 Gbit/s
0,011694 €
7,29 €
L4 Cores8 GB80 GB10 TB1 Gbit/s
0,023389 €
14,59 €
XL8 Cores16 GB160 GB10 TB1 Gbit/s
0,038312 €
23,91 €

Standard

ModelCPU RAM StorageTraffic BandwidthPrice/hourPrice/month
XS1 Core4 GB40 GB20 TB2.5 Gbit/s
0,014303 €
8,93 €
S2 Cores8 GB80 GB20 TB2.5 Gbit/s
0,024579 €
15,34 €
M4 Cores16 GB160 GB20 TB2.5 Gbit/s
0,049158 €
30,68 €
L8 Cores24 GB240 GB20 TB2.5 Gbit/s
0,093740 €
58,49 €
XL10 Cores32 GB360 GB20 TB2.5 Gbit/s
0,120608 €
75,26 €
XXL16 Cores64 GB500 GB20 TB2.5 Gbit/s
0,188623 €
117,70 €

Performance

ModelCPU RAM StorageTraffic BandwidthPrice/hourPrice/month
S2 Cores16 GB80 GB20 TB10 Gbit/s
0,070561 €
44,03 €
M4 Cores32 GB160 GB20 TB10 Gbit/s
0,141122 €
88,06 €
L8 Cores64 GB240 GB20 TB10 Gbit/s
0,277666 €
173,26 €
XL16 Cores128 GB360 GB20 TB10 Gbit/s
0,548467 €
342,24 €
XXL32 Cores192 GB500 GB20 TB10 Gbit/s
1,011118 €
630,94 €

Create it via the Public API

A single call creates this Seed. Replace the placeholders starting with $ with your own values, such as your API token and the IDs from your account. Go to the Public API

bash
curl -X POST "https://api.dataforest.net/api/v1/public/seeds" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "plan": "lines/entry/models/entry-c1-m2-s20",
  "location": "fra01",
  "source": {
    "type": "app",
    "ref": "apps/wireguard/versions/wireguard-v1.0.20210914",
    "environment_variables": {
      "WG_DNS": "$WG_DNS"
    }
  },
  "project_id": "$PROJECT_ID",
  "name": "wireguard"
}'

Our cloud newsletter

Stay up to date and get valuable tips by subscribing to our newsletter.

Any questions?

Our experts are happy to help. You'll be surprised how fast we are.

Background image