Guide

Configurer un VPN WireGuard sur un VPS en 5 minutes

DébutantLecture de 5 minMis à jour 30 mai 2026
Réponse courte

Un serveur WireGuard fonctionnel nécessite quatre choses : une paire de clés, une configuration d'interface wg0, le routage IP avec NAT, et un bloc pair pour chaque appareil. Sur une instance à $4, tout le processus prend environ cinq minutes et saturera un port gigabit.

01 Installer WireGuard et générer les clés

The kernel module is already present on any modern Linux distribution running on KVM.

apt update && apt install -y wireguard
umask 077
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub

02 Écrire la configuration du serveur

Replace eth0 with your actual interface name if it differs — check with ip -br link. The Address line defines the tunnel subnet, not your public address.

# /etc/wireguard/wg0.conf
[Interface]
Address = 10.66.66.1/24, fd42:42::1/64
ListenPort = 51820
PrivateKey = <contents of /etc/wireguard/server.key>
PostUp   = nft add table ip nat; nft add chain ip nat post { type nat hook postrouting priority 100 \; }; nft add rule ip nat post oifname "eth0" masquerade
PostDown = nft delete table ip nat

03 Activer le transfert et démarrer le tunnel

Forwarding must be enabled for both address families, or IPv6 clients will fail silently.

cat >/etc/sysctl.d/99-wg.conf <<'EOF'
net.ipv4.ip_forward=1
net.ipv6.conf.all.forwarding=1
EOF
sysctl --system
systemctl enable --now wg-quick@wg0
ufw allow 51820/udp

04 Ajouter un pair pour chaque appareil

Generate a key pair per device. AllowedIPs on the server side is the address that device will hold inside the tunnel — not a range.

wg set wg0 peer <CLIENT_PUBLIC_KEY> allowed-ips 10.66.66.2/32,fd42:42::2/128
wg-quick save wg0

05 Configuration du client

AllowedIPs of 0.0.0.0/0 and ::/0 routes all traffic through the tunnel. Narrow it for split tunnelling.

[Interface]
PrivateKey = <client private key>
Address = 10.66.66.2/32, fd42:42::2/128
DNS = 10.66.66.1

[Peer]
PublicKey = <server public key>
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

Questions fréquemment posées

Combien d'appareils un VPS peut-il gérer ?

Un seul cœur partagé gère confortablement 20+ pairs simultanés. La limite est votre liaison montante, pas l'instance.

Pourquoi ma connexion est-elle lente ?

Presque toujours le MTU. Essayez MTU = 1420 sur l'interface du client ; WireGuard ajoute un surcoût qui peut pousser les paquets au-delà du MTU du chemin et déclencher la fragmentation.