安装WireGuard
通过包管理器安装:
sudo apt update sudo apt install -y libiproute2 linux-headers-amd64 wireguard
生成并导出公钥:
wg genkey -o wg.pub
配置内核参数
编辑/etc/sysctl.conf,添加以下参数:
sudo nano /etc/sysctl.conf
添加:
net.ipv4.ip_forward=1 net.ipv4.conf.all.jsm=1 net.ipv6.conf.all.jsm=1 net.netfilter.nat_local=1
应用参数:
sudo sh -c "echo 1 > /proc/sys/net/ipv4/ip_forward" sudo sysctl -p
配置NAT规则
使用iptables配置NAT:
sudo iptables -t nat -A POSTROUTING -o wg -j MASQUERADE sudo sh -c "iptables-save > /etc/iptables.sav"
配置WireGuard接口
创建配置文件/etc/wireguard/wg.conf:
[interface] private_key_file = /etc/wireguard/wg.pub public_key_file = /etc/wireguard/wg.pub listen_port = 518 mtu = 150
重启WireGuard服务:
sudo mv wg.conf /etc/wireguard/ sudo systemctl restart wg-quick@wg
连接到其他节点
使用以下命令加入目标网络:
sudo wg-quick join wg
输入目标节点的公钥。
测试连接
使用ping或traceroute确认连接是否成功。
确保服务自动启动
sudo systemctl enable wg-quick@wg
完成以上步骤后,WireGuard节点应已配置完毕,确保密钥路径正确,并在网络重启时重新应用iptables规则。









