# How to Configure VPN Access with WireGuard on pfSense

> Learn to configure WireGuard VPN on pfSense easily. Install the package, create tunnels, and set up secure peer access for remote connectivity.

- Repository: [Michael Royal/Self-Hosting-Guide](https://github.com/mikeroyal/Self-Hosting-Guide)
- Tags: how-to-guide
- Published: 2026-06-17

---

**WireGuard VPN on pfSense is configured by installing the official package, creating a tunnel interface with autogenerated keys, enabling the service, and defining peers with public key authentication.**

This guide walks you through configuring secure VPN access using WireGuard on pfSense, based on the authoritative source code and documentation in the mikeroyal/Self-Hosting-Guide repository. WireGuard operates as a kernel module on FreeBSD-based firewalls, providing state-of-the-art cryptography with significantly lower overhead than traditional IPsec solutions.

## Understanding the WireGuard Architecture on pfSense

According to the mikeroyal/Self-Hosting-Guide source, the implementation consists of four core components that work together to create an encrypted tunnel:

- **WireGuard Package** – Installs the kernel module and GUI front-end integrated into pfSense.
- **Tunnel Interface** – A virtual network interface (typically `wg0`) that carries all encrypted traffic.
- **Peers** – Remote client devices identified by public keys that the server trusts for authentication.
- **Firewall Rules** –pfSense rules that permit UDP traffic on the listen port (default **51820**) and route traffic between VPN and LAN zones.

WireGuard utilizes **kernel-level encryption** with ChaCha20-Poly1305, offering constant-time cryptography without the processing overhead of userspace VPN daemons. The protocol is stateless, meaning the server does not maintain per-connection state, which simplifies scaling and improves resistance to denial-of-service attacks.

## Installing the WireGuard Package

The first step is installing the package from the pfSense repository. As documented in [`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md) at line 4199, navigate to **System → Package Manager** and search for **WireGuard**. Install the latest version to add the kernel module and web interface components to your firewall.

## Creating and Configuring the WireGuard Tunnel

Once installed, create the tunnel interface by following the steps outlined in [`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md) lines 4222-4229:

1. Navigate to **VPN → WireGuard → Tunnels** and click **Add Tunnel**.
2. Set a **Description** (e.g., "WireGuard") and specify the **Listen Port** as `51820`.
3. Click **Generate** to create a private/public key pair for the server.
4. Copy the **Public Key** displayed in the interface—you will need this value for each client configuration (specifically referenced at line 4226).

After creating the tunnel, enable the service by going to **Settings**, ticking **Enable WireGuard**, then clicking **Save** and **Apply** as shown at line 4228.

## Configuring Firewall Rules for VPN Access

To allow incoming VPN connections, you must create firewall rules that permit UDP traffic on the WireGuard listen port:

- Navigate to **Firewall → Rules → WAN** (or the interface facing your clients).
- Create a new rule allowing **UDP** traffic on port **51820**.
- Optionally restrict the **Source IP** to specific ranges for additional security.

These rules integrate with pfSense’s existing NAT engine, allowing you to apply the same filtering logic used for other network traffic.

## Adding Peer Configurations

With the tunnel active, define each remote device as a peer. According to [`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md) line 4240, configure peers under the tunnel settings:

1. Click **Add Peer** within the tunnel configuration.
2. Paste the client’s **Public Key** into the appropriate field.
3. Set the **Allowed IPs** to the specific IP address assigned to that client (e.g., `10.0.0.2/32` for a single client or `10.0.0.0/24` for a subnet).

Each peer requires a unique allowed IP range to prevent address conflicts within the VPN subnet.

## Client Configuration and Key Generation

To generate cryptographic keys for clients, use the `wg` command-line tool on any Linux or Unix host:

```bash

# Generate server keys (if not using pfSense GUI)

wg genkey | tee server_private.key | wg pubkey > server_public.key

# Generate client keys

wg genkey | tee client_private.key | wg pubkey > client_public.key

```

Use these keys to populate the configuration files. Below is the minimal configuration for the **pfSense server** (wg0 interface):

```ini
[Interface]
PrivateKey = <SERVER_PRIVATE_KEY>
ListenPort = 51820
Address = 10.0.0.1/24
DNS = 1.1.1.1

```

For **client devices**, use this configuration template, replacing placeholders with actual values:

```ini
[Interface]
PrivateKey = <CLIENT_PRIVATE_KEY>
Address = 10.0.0.2/32
DNS = 1.1.1.1

[Peer]
PublicKey = <SERVER_PUBLIC_KEY>
Endpoint = <PF_SENSE_PUBLIC_IP>:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

```

The `PersistentKeepalive` setting ensures NAT traversal by keeping the connection alive, typically set to 25 seconds.

## Summary

Configuring VPN access with WireGuard on pfSense involves these key steps:

- Install the WireGuard package from **System → Package Manager** (as shown at line 4199).
- Create a tunnel at **VPN → WireGuard → Tunnels** and generate cryptographic keys (lines 4222-4229).
- Enable the service in **Settings** and copy the server public key for client configuration (line 4228).
- Configure firewall rules to allow UDP traffic on port 51820.
- Add peers with specific allowed IPs and public key authentication (line 4240).

## Frequently Asked Questions

### What is the default port for WireGuard on pfSense?

The default **Listen Port** for WireGuard on pfSense is **51820**, which must be opened in your WAN firewall rules to accept incoming VPN connections. This port operates over UDP and should be restricted to specific source IPs when possible for enhanced security.

### Does WireGuard run in the kernel on pfSense?

Yes, WireGuard operates as a **kernel module** on FreeBSD-based systems like pfSense, utilizing kernel-level encryption with ChaCha20-Poly1305. This architecture provides lower latency and higher throughput compared to userspace VPN implementations.

### How do I generate keys for WireGuard clients?

Generate keys using the `wg` command-line utility on any Linux or Unix system: `wg genkey | tee private.key | wg pubkey > public.key`. Paste the contents of `public.key` into the peer configuration on pfSense, and use `private.key` in the client’s WireGuard application or configuration file.

### Can I use WireGuard for site-to-site VPNs on pfSense?

Yes, WireGuard supports both **remote access** (road warrior) and **site-to-site** configurations. For site-to-site setups, configure both pfSense instances as peers with each other’s public keys, and set appropriate **Allowed IPs** to cover the remote networks rather than individual client addresses.