Rehber

Bir VPS üzerinde 5 dakikada WireGuard VPN kurun

Başlangıç seviyesi5 dk okumaGüncellendi 30 Mayıs 2026
Kısa cevap

Çalışan bir WireGuard sunucusu dört şey gerektirir: bir anahtar çifti, bir wg0 arayüz yapılandırması, NAT ile IP yönlendirme ve cihaz başına bir eş bloğu. 4 dolarlık bir örnekte tüm süreç yaklaşık beş dakika sürer ve bir gigabit bağlantı noktasını doyurur.

01 WireGuard kurulumu ve anahtar oluşturma

The kernel module is already present on any modern Linux distribution running on KVM.

apt update && apt install -y wireguard
umask 077
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub

02 Sunucu yapılandırmasını yazın

Replace eth0 with your actual interface name if it differs — check with ip -br link. The Address line defines the tunnel subnet, not your public address.

# /etc/wireguard/wg0.conf
[Interface]
Address = 10.66.66.1/24, fd42:42::1/64
ListenPort = 51820
PrivateKey = <contents of /etc/wireguard/server.key>
PostUp   = nft add table ip nat; nft add chain ip nat post { type nat hook postrouting priority 100 \; }; nft add rule ip nat post oifname "eth0" masquerade
PostDown = nft delete table ip nat

03 Yönlendirmeyi etkinleştirin ve tüneli başlatın

Forwarding must be enabled for both address families, or IPv6 clients will fail silently.

cat >/etc/sysctl.d/99-wg.conf <<'EOF'
net.ipv4.ip_forward=1
net.ipv6.conf.all.forwarding=1
EOF
sysctl --system
systemctl enable --now wg-quick@wg0
ufw allow 51820/udp

04 Her cihaz için bir eş (peer) ekleyin

Generate a key pair per device. AllowedIPs on the server side is the address that device will hold inside the tunnel — not a range.

wg set wg0 peer <CLIENT_PUBLIC_KEY> allowed-ips 10.66.66.2/32,fd42:42::2/128
wg-quick save wg0

05 İstemci yapılandırması

AllowedIPs of 0.0.0.0/0 and ::/0 routes all traffic through the tunnel. Narrow it for split tunnelling.

[Interface]
PrivateKey = <client private key>
Address = 10.66.66.2/32, fd42:42::2/128
DNS = 10.66.66.1

[Peer]
PublicKey = <server public key>
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

Sık sorulan sorular

Bir VPS kaç cihazı kaldırabilir?

Tek bir paylaşımlı çekirdek, 20'den fazla eş zamanlı eşi rahatça kaldırır. Sınır, örnek değil, yukarı bağlantınızdır.

Bağlantım neden yavaş?

Neredeyse her zaman MTU'dur. İstemci arayüzünde MTU = 1420 deneyin; WireGuard, paketleri yol MTU'sunun üzerine itip parçalanmaya neden olabilecek ek yük ekler.