The server is hardened, but SSH still answers the whole internet. This page builds the private path that will replace it: WireGuard on the server, on a single UDP port, and your Mac connected to it with a key generated on each device. At the end, ssh goes through the tunnel. The old door stays open for the whole page: it only closes on page 2, once the tunnel is proven.
Before you start
$ssh vps 'test -x /usr/sbin/ufw && echo ready'ready
Install WireGuard on your Mac
Install WireGuard from the Mac App Store (publisher: WireGuard Development Team). Open it, then + at the bottom left → Add Empty Tunnel…. Name it . The app generates a key pair and shows the public key at the top of the editor.
Copy that public key into the Mac public key field of the values panel, then save the tunnel as it is. It is incomplete: part 3 finishes it. macOS asks to allow adding a VPN configuration: accept.
Install WireGuard on the server
In your ssh vps session, install the tools and generate the server's key into a file only root can read:
$sudo apt update && sudo apt install -y wireguard-tools$sudo install -d -m 700 /etc/wireguard$sudo sh -c 'umask 077 && wg genkey > /etc/wireguard/wg0.key'Write the server configuration
Create /etc/wireguard/wg0.conf with sudo vim:
[Interface]Address = /24ListenPort = PostUp = wg set %i private-key /etc/wireguard/%i.key[Peer]# macPublicKey = AllowedIPs = /32Then restrict its mode: sudo chmod 600 /etc/wireguard/wg0.conf.
Open the port and start
Open the UDP port in the firewall, start the interface and have it come back on every boot, then print the server's public key:
$sudo ufw allow /udp$sudo systemctl enable --now wg-quick@wg0$sudo wg show wg0 public-keyCopy the key it prints into the Server public key field of the values panel.
$ssh vps systemctl is-active wg-quick@wg0active
Connect the Mac
In the WireGuard app on the Mac, select the tunnel, Edit. Keep the first line PrivateKey = … and add this below it:
Address = /32[Peer]PublicKey = AllowedIPs = /32Endpoint = :Save, then Activate. From a terminal:
$ping -c 3 | grep -o '3 packets received'3 packets received
If the ping gets no answer
In order:
- On the server,
sudo wg show: does themacpeer have alatest handshake? If not, compare both public keys, character by character. sudo ufw statusmust show/udp ALLOW.- In the app, is the tunnel really Active? Does
Data receivedgo up? - OVH's Network Firewall, if you turned it on for the IP, filters before the VPS: add a UDP rule for
. - A network that blocks outbound UDP (some public Wi-Fi): try from your phone's hotspot.
Go through the tunnel
Add an ssh shortcut on your Mac that targets the server's tunnel address, then connect with it:
$touch ~/.ssh/config && chmod 600 ~/.ssh/config$grep -q '^Host $' ~/.ssh/config || printf '\nHost \n HostName \n Port \n User \n IdentityFile \n IdentitiesOnly yes\n AddKeysToAgent yes\n UseKeychain yes\n' >> ~/.ssh/config$ssh echo via-wireguardssh does not know this address yet and asks you to confirm the host key. Before answering yes, compare the fingerprint it shows with the server's, read through the old door:
$ssh vps ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub$ssh echo via-wireguardvia-wireguard
Done
| What | Before | After this page |
|---|---|---|
| Paths to the server | ssh vps, over the internet | ssh vps and ssh , through the tunnel |
| Open ports | /tcp | /tcp and /udp |
| Devices in the tunnel | none | your Mac, each with its own key |
Next page: Close the public door. It takes /tcp off the internet, keeps SSH on the tunnel only, and proves everything comes back after a reboot.