Panduan

Siapkan VPN WireGuard di VPS dalam 5 menit

Pemula5 menit bacaDiperbarui 30 Mei 2026
Jawaban singkat

Server WireGuard yang berfungsi membutuhkan empat hal: sepasang kunci, konfigurasi antarmuka wg0, penerusan IP dengan NAT, dan satu blok peer per perangkat. Pada instance $4, seluruh proses memakan waktu sekitar lima menit dan akan memenuhi port gigabit.

01 Pasang WireGuard dan buat kunci

The kernel module is already present on any modern Linux distribution running on KVM.

apt update && apt install -y wireguard
umask 077
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub

02 Tulis konfigurasi server

Replace eth0 with your actual interface name if it differs — check with ip -br link. The Address line defines the tunnel subnet, not your public address.

# /etc/wireguard/wg0.conf
[Interface]
Address = 10.66.66.1/24, fd42:42::1/64
ListenPort = 51820
PrivateKey = <contents of /etc/wireguard/server.key>
PostUp   = nft add table ip nat; nft add chain ip nat post { type nat hook postrouting priority 100 \; }; nft add rule ip nat post oifname "eth0" masquerade
PostDown = nft delete table ip nat

03 Aktifkan penerusan dan mulai tunnel

Forwarding must be enabled for both address families, or IPv6 clients will fail silently.

cat >/etc/sysctl.d/99-wg.conf <<'EOF'
net.ipv4.ip_forward=1
net.ipv6.conf.all.forwarding=1
EOF
sysctl --system
systemctl enable --now wg-quick@wg0
ufw allow 51820/udp

04 Tambahkan peer untuk setiap perangkat

Generate a key pair per device. AllowedIPs on the server side is the address that device will hold inside the tunnel — not a range.

wg set wg0 peer <CLIENT_PUBLIC_KEY> allowed-ips 10.66.66.2/32,fd42:42::2/128
wg-quick save wg0

05 Konfigurasi klien

AllowedIPs of 0.0.0.0/0 and ::/0 routes all traffic through the tunnel. Narrow it for split tunnelling.

[Interface]
PrivateKey = <client private key>
Address = 10.66.66.2/32, fd42:42::2/128
DNS = 10.66.66.1

[Peer]
PublicKey = <server public key>
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

Pertanyaan yang sering diajukan

Berapa banyak perangkat yang bisa ditangani satu VPS?

Satu inti bersama dengan nyaman menangani 20+ peer bersamaan. Batasnya adalah uplink Anda, bukan instansnya.

Mengapa koneksi saya lambat?

Hampir selalu MTU. Coba MTU = 1420 pada antarmuka klien; WireGuard menambah overhead yang bisa mendorong paket melewati MTU jalur dan memicu fragmentasi.