← Back to Documentation

WireGuard Client Quickstart Guide

Learn how to bootstrap a new client node from scratch in under 3 minutes using wg-init.

Step 1: Install WireGuard and Tools

Before running wg-init, ensure that the WireGuard kernel module/tools and resolvconf (or openresolv) are installed on your Linux client:

Installing prerequisites
# On Debian / Ubuntu
sudo apt update && sudo apt install -y wireguard openresolv

# On Arch Linux
sudo pacman -S wireguard-tools openresolv

# On Fedora / RHEL
sudo dnf install -y wireguard-tools systemd-resolved

Step 2: Install wg-init

Download and install wg-init using the one-line bootstrap installer:

Install wg-init
curl https://raw.githubusercontent.com/joshuacox/wg-init/refs/heads/main/bootstrap | bash

Step 3: Collect Server Parameters

Obtain the connection parameters from your WireGuard server administrator or your VPN host:

  • Server Public Key: e.g., v8mBq...=
  • Server Public Endpoint: e.g., vpn.company.com:51820
  • Assigned Client IP: e.g., 10.100.0.4/24
  • Internal DNS Resolver: e.g., 10.100.0.1
  • Allowed IPs: e.g., 10.100.0.0/24 (split tunnel) or 0.0.0.0/0 (full tunnel)

Step 4: Execute wg-init

Run wg-init with the environment variables set:

Execute bootstrap
MyAddress=10.100.0.4/24 \
MyDNS=10.100.0.1 \
PeerPublicKey='v8mBqK8Z...' \
PeerAllowedIPs='10.100.0.0/24' \
PeerEndpoint='vpn.company.com:51820' \
wg-init

Step 5: Exchange Public Key & Start Tunnel

Copy the public key printed on the screen and add it to your server configuration:

Server-side peer authorization
# On the WireGuard Server:
sudo wg set wg0 peer <CLIENT_PUBLIC_KEY> allowed-ips 10.100.0.4/32

Then, bring up your connection on your client machine using wg-quick:

Start and verify connection
# Bring up tunnel
sudo wg-quick up wg0

# Verify active handshake and transfer stats
sudo wg show

# Test ping through the encrypted tunnel
ping -c 3 10.100.0.1