Open a WireGuard tunnel to the server

WireGuard running on the server on one UDP port, your Mac (and your phone if you want) connected to it with keys generated on each device, and ssh reaching the server through the tunnel under a new shortcut. The public SSH port stays open: page 2 closes it.

intermediate~25 min hands-on
#wireguard#vpn#ssh#ufw#debian#macos#security

Not validated end to end yet — be the first.Report a problem

Draft — not yet run end to end. This page was written but its author has not yet run it on a real machine. Commands may be wrong: read before you run, and tell us what breaks.

The gistA second way in, private
Your devices
Your VPS
WireGuardUDP TCP
Your Macssh
InternetUDP
wg0
sshd:

Your Mac reaches ${WG_SERVER_ADDR} through an encrypted UDP tunnel to ${SERVER_IP}:${WG_PORT}, then opens an SSH session inside it. The public SSH port is still open on this page.

The server is hardened, but SSH still answers the whole internet. This page builds the private path that will replace it: WireGuard on the server, on a single UDP port, and your Mac connected to it with a key generated on each device. At the end, ssh goes through the tunnel. The old door stays open for the whole page: it only closes on page 2, once the tunnel is proven.

Before you start

Check
$ssh vps 'test -x /usr/sbin/ufw && echo ready'
Expected output
ready

Install WireGuard on your Mac

Install WireGuard from the Mac App Store (publisher: WireGuard Development Team). Open it, then + at the bottom left → Add Empty Tunnel…. Name it . The app generates a key pair and shows the public key at the top of the editor.

Copy that public key into the Mac public key field of the values panel, then save the tunnel as it is. It is incomplete: part 3 finishes it. macOS asks to allow adding a VPN configuration: accept.

Install WireGuard on the server

In your ssh vps session, install the tools and generate the server's key into a file only root can read:

Server·
Sensitive command — overwrites a system file. Review before running.
$sudo apt update && sudo apt install -y wireguard-tools
$sudo install -d -m 700 /etc/wireguard
$sudo sh -c 'umask 077 && wg genkey > /etc/wireguard/wg0.key'

Write the server configuration

Create /etc/wireguard/wg0.conf with sudo vim:

Server·writes a file/etc/wireguard/wg0.conf
[Interface]
Address = /24
ListenPort =
PostUp = wg set %i private-key /etc/wireguard/%i.key
[Peer]
# mac
PublicKey =
AllowedIPs = /32

Then restrict its mode: sudo chmod 600 /etc/wireguard/wg0.conf.

Open the port and start

Open the UDP port in the firewall, start the interface and have it come back on every boot, then print the server's public key:

Server·
$sudo ufw allow /udp
$sudo systemctl enable --now wg-quick@wg0
$sudo wg show wg0 public-key

Copy the key it prints into the Server public key field of the values panel.

Check
$ssh vps systemctl is-active wg-quick@wg0
Expected output
active

Connect the Mac

In the WireGuard app on the Mac, select the tunnel, Edit. Keep the first line PrivateKey = … and add this below it:

Tunnel ${SSH_ALIAS} — WireGuard app on the Mac
Address = /32
[Peer]
PublicKey =
AllowedIPs = /32
Endpoint = :

Save, then Activate. From a terminal:

Check
$ping -c 3  | grep -o '3 packets received'
Expected output
3 packets received
If the ping gets no answer

In order:

  • On the server, sudo wg show: does the mac peer have a latest handshake? If not, compare both public keys, character by character.
  • sudo ufw status must show /udp ALLOW.
  • In the app, is the tunnel really Active? Does Data received go up?
  • OVH's Network Firewall, if you turned it on for the IP, filters before the VPS: add a UDP rule for .
  • A network that blocks outbound UDP (some public Wi-Fi): try from your phone's hotspot.

Go through the tunnel

Add an ssh shortcut on your Mac that targets the server's tunnel address, then connect with it:

Mac
$touch ~/.ssh/config && chmod 600 ~/.ssh/config
$grep -q '^Host $' ~/.ssh/config || printf '\nHost \n HostName \n Port \n User \n IdentityFile \n IdentitiesOnly yes\n AddKeysToAgent yes\n UseKeychain yes\n' >> ~/.ssh/config
$ssh echo via-wireguard

ssh does not know this address yet and asks you to confirm the host key. Before answering yes, compare the fingerprint it shows with the server's, read through the old door:

Mac
$ssh vps ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
Check
$ssh  echo via-wireguard
Expected output
via-wireguard

Done

WhatBeforeAfter this page
Paths to the serverssh vps, over the internetssh vps and ssh , through the tunnel
Open ports/tcp/tcp and /udp
Devices in the tunnelnoneyour Mac, each with its own key

Next page: Close the public door. It takes /tcp off the internet, keeps SSH on the tunnel only, and proves everything comes back after a reboot.

Did everything work?

If you followed this page to the end on a real machine, say so. Your validation is dated and records your stack, so the next reader on the same path knows it still works.

This copy is read-only. To report that it works, or that it does not, open an issue

Only your stack choices are recorded, never your values. The pseudonym stays on this browser.