How to Configure VPN Access with WireGuard on pfSense

WireGuard VPN on pfSense is configured by installing the official package, creating a tunnel interface with autogenerated keys, enabling the service, and defining peers with public key authentication.

This guide walks you through configuring secure VPN access using WireGuard on pfSense, based on the authoritative source code and documentation in the mikeroyal/Self-Hosting-Guide repository. WireGuard operates as a kernel module on FreeBSD-based firewalls, providing state-of-the-art cryptography with significantly lower overhead than traditional IPsec solutions.

Understanding the WireGuard Architecture on pfSense

According to the mikeroyal/Self-Hosting-Guide source, the implementation consists of four core components that work together to create an encrypted tunnel:

  • WireGuard Package – Installs the kernel module and GUI front-end integrated into pfSense.
  • Tunnel Interface – A virtual network interface (typically wg0) that carries all encrypted traffic.
  • Peers – Remote client devices identified by public keys that the server trusts for authentication.
  • Firewall Rules –pfSense rules that permit UDP traffic on the listen port (default 51820) and route traffic between VPN and LAN zones.

WireGuard utilizes kernel-level encryption with ChaCha20-Poly1305, offering constant-time cryptography without the processing overhead of userspace VPN daemons. The protocol is stateless, meaning the server does not maintain per-connection state, which simplifies scaling and improves resistance to denial-of-service attacks.

Installing the WireGuard Package

The first step is installing the package from the pfSense repository. As documented in README.md at line 4199, navigate to System → Package Manager and search for WireGuard. Install the latest version to add the kernel module and web interface components to your firewall.

Creating and Configuring the WireGuard Tunnel

Once installed, create the tunnel interface by following the steps outlined in README.md lines 4222-4229:

  1. Navigate to VPN → WireGuard → Tunnels and click Add Tunnel.
  2. Set a Description (e.g., "WireGuard") and specify the Listen Port as 51820.
  3. Click Generate to create a private/public key pair for the server.
  4. Copy the Public Key displayed in the interface—you will need this value for each client configuration (specifically referenced at line 4226).

After creating the tunnel, enable the service by going to Settings, ticking Enable WireGuard, then clicking Save and Apply as shown at line 4228.

Configuring Firewall Rules for VPN Access

To allow incoming VPN connections, you must create firewall rules that permit UDP traffic on the WireGuard listen port:

  • Navigate to Firewall → Rules → WAN (or the interface facing your clients).
  • Create a new rule allowing UDP traffic on port 51820.
  • Optionally restrict the Source IP to specific ranges for additional security.

These rules integrate with pfSense’s existing NAT engine, allowing you to apply the same filtering logic used for other network traffic.

Adding Peer Configurations

With the tunnel active, define each remote device as a peer. According to README.md line 4240, configure peers under the tunnel settings:

  1. Click Add Peer within the tunnel configuration.
  2. Paste the client’s Public Key into the appropriate field.
  3. Set the Allowed IPs to the specific IP address assigned to that client (e.g., 10.0.0.2/32 for a single client or 10.0.0.0/24 for a subnet).

Each peer requires a unique allowed IP range to prevent address conflicts within the VPN subnet.

Client Configuration and Key Generation

To generate cryptographic keys for clients, use the wg command-line tool on any Linux or Unix host:


# Generate server keys (if not using pfSense GUI)

wg genkey | tee server_private.key | wg pubkey > server_public.key

# Generate client keys

wg genkey | tee client_private.key | wg pubkey > client_public.key

Use these keys to populate the configuration files. Below is the minimal configuration for the pfSense server (wg0 interface):

[Interface]
PrivateKey = <SERVER_PRIVATE_KEY>
ListenPort = 51820
Address = 10.0.0.1/24
DNS = 1.1.1.1

For client devices, use this configuration template, replacing placeholders with actual values:

[Interface]
PrivateKey = <CLIENT_PRIVATE_KEY>
Address = 10.0.0.2/32
DNS = 1.1.1.1

[Peer]
PublicKey = <SERVER_PUBLIC_KEY>
Endpoint = <PF_SENSE_PUBLIC_IP>:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25

The PersistentKeepalive setting ensures NAT traversal by keeping the connection alive, typically set to 25 seconds.

Summary

Configuring VPN access with WireGuard on pfSense involves these key steps:

  • Install the WireGuard package from System → Package Manager (as shown at line 4199).
  • Create a tunnel at VPN → WireGuard → Tunnels and generate cryptographic keys (lines 4222-4229).
  • Enable the service in Settings and copy the server public key for client configuration (line 4228).
  • Configure firewall rules to allow UDP traffic on port 51820.
  • Add peers with specific allowed IPs and public key authentication (line 4240).

Frequently Asked Questions

What is the default port for WireGuard on pfSense?

The default Listen Port for WireGuard on pfSense is 51820, which must be opened in your WAN firewall rules to accept incoming VPN connections. This port operates over UDP and should be restricted to specific source IPs when possible for enhanced security.

Does WireGuard run in the kernel on pfSense?

Yes, WireGuard operates as a kernel module on FreeBSD-based systems like pfSense, utilizing kernel-level encryption with ChaCha20-Poly1305. This architecture provides lower latency and higher throughput compared to userspace VPN implementations.

How do I generate keys for WireGuard clients?

Generate keys using the wg command-line utility on any Linux or Unix system: wg genkey | tee private.key | wg pubkey > public.key. Paste the contents of public.key into the peer configuration on pfSense, and use private.key in the client’s WireGuard application or configuration file.

Can I use WireGuard for site-to-site VPNs on pfSense?

Yes, WireGuard supports both remote access (road warrior) and site-to-site configurations. For site-to-site setups, configure both pfSense instances as peers with each other’s public keys, and set appropriate Allowed IPs to cover the remote networks rather than individual client addresses.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →