The tunnel works: SSH no longer needs to be on the internet. This page opens SSH on the tunnel interface, removes the public rule, checks from outside that the door is really closed, and reboots the server to prove everything comes back on its own. Before closing, it puts the way back in somewhere safe: the KVM console, and a copy of your keys.
Before you start
$ssh echo via-wireguardvia-wireguard
Keep the way back in
After this page, two things open the server: your Mac (its WireGuard key and its SSH key), and the KVM console in the OVH control panel. Check the second one now, and make a copy of the first.
Then store in your password manager:
- the SSH key
(the private file, already encrypted by its passphrase); - the tunnel configuration, exported from the WireGuard app on the Mac (menu Tunnels or File → Export Tunnels to Zip…).
Take a snapshot
Open SSH on the tunnel only
In your ssh session, allow SSH on the wg0 interface, then remove the public rule:
$sudo ufw allow in on wg0 to any port proto tcp$sudo ufw delete allow /tcp$sudo ufw status verboseufw status must now show two rules (plus their (v6) twins): /udp ALLOW IN Anywhere and /tcp on wg0 ALLOW IN Anywhere.
Check from outside
From your Mac, try the public door: it must not answer. Then go back through the tunnel:
$nc -z -G 5 >/dev/null 2>&1 && echo "public door: STILL OPEN" || echo "public door: closed"$ssh echo via-wireguard$nc -z -G 5 >/dev/null 2>&1 && echo open || echo closedclosed
Remove the vps shortcut
ssh vps leads nowhere now. Remove its block from ~/.ssh/config, keeping a copy:
$cp ~/.ssh/config ~/.ssh/config.bak$awk '/^Host[[:space:]]/ { skip = ($2 == "vps") } !skip' ~/.ssh/config.bak > ~/.ssh/configProve it survives a reboot
A setting that does not survive a reboot will lock you out one day, on the night of an automatic update. Reboot now, while you are watching:
$ssh -t sudo systemctl rebootWait a minute, then:
$ssh systemctl is-active wg-quick@wg0active
If the tunnel breaks
Get in through the KVM console and reopen SSH while you repair
In the OVH control panel, open the KVM console, log in as with your password. Reopen the public door:
$sudo ufw allow /tcpYou can now get in from your Mac through the public address, with your key, and diagnose in comfort:
$ssh -p -i -o IdentitiesOnly=yes @On the server, sudo systemctl status wg-quick@wg0, sudo wg show and journalctl -u wg-quick@wg0 almost always tell what is wrong. Once ssh is back, close again: sudo ufw delete allow ${SSH_PORT}/tcp.
If you lost the Mac
On the new computer, import the exported tunnel and the SSH key stored above: everything works again, nothing to change on the server. Then revoke the old Mac, since its WireGuard key still exists somewhere: generate a new pair in the app, replace PublicKey in the # mac block of /etc/wireguard/wg0.conf, sudo systemctl restart wg-quick@wg0, and remove the old SSH key from ~/.ssh/authorized_keys.
Without a copy of the keys, the KVM console remains: reopen the public door as above, then add the new SSH public key to ~/.ssh/authorized_keys. Typing it in the console is painful (and sensitive to the keyboard layout); OVH's rescue mode lets you edit the file from another system.
What is still visible
Seen from the internet, your server now answers ping, and nothing else. Port /udp is open, but mute to anyone without a key.
Done
| What | Before | After this page |
|---|---|---|
| Ports open to the internet | /tcp, /udp | /udp only, mute without a key |
| SSH | reachable from the whole internet | through the tunnel only, ssh |
| After a reboot | untested | proven |
| Way back in | KVM console | KVM console, keys stored, step back in one command |
The server is now private: only your devices get in. The rest of the series installs what should live there, listening only on .