VPN 指南 · 1 分钟阅读

如何在VPS上在10分钟内设置WireGuard

WireGuard是最快、最简单的现代VPN协议,在便宜的VPS上搭建自己的服务器只需几分钟。这里是完整的服务器和客户端配置,以及使其路由的一个NAT规则,以及如何验证它。

为什么选择 WireGuard,以及你正在构建的内容

WireGuard 是一种现代 VPN 协议,内置于 Linux 内核中:几百行代码,最先进的加密技术(ChaCha20,Curve25519),以及小到可以在屏幕上显示的配置。与 OpenVPN 相比,它连接更快,运行更快,且更易于理解 — 参见 WireGuard vs OpenVPN。在 VPS 上搭建自己的服务器可以让你拥有一个私有的全隧道出口,其 IP 地址仅属于你。

构建分为四个部分:安装 WireGuard,为每个对等方生成密钥对,编写将客户端流量 NAT 到互联网的服务器配置,以及编写指向服务器的客户端配置。整个过程实际上只需大约十分钟。

服务器和客户端配置

在新的 VPS 上运行。生成密钥,编写服务器接口,添加伪装规则,然后创建匹配的客户端配置。替换 VPS_PUBLIC_IP 和密钥。

bash
# --- 1. install & generate keys (server) ---
apt update && apt install -y wireguard
cd /etc/wireguard && umask 077
wg genkey | tee server.key | wg pubkey > server.pub
wg genkey | tee client.key | wg pubkey > client.pub

# --- 2. /etc/wireguard/wg0.conf (server) ---
cat > /etc/wireguard/wg0.conf <<CFG
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = $(cat server.key)
# NAT client traffic out to the internet (eth0 = your WAN iface):
PostUp   = iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE

[Peer]
PublicKey = $(cat client.pub)
AllowedIPs = 10.8.0.2/32
CFG

# --- 3. enable IP forwarding & start ---
echo 'net.ipv4.ip_forward=1' >> /etc/sysctl.conf && sysctl -p
systemctl enable --now wg-quick@wg0

# --- 4. client config (put on your laptop/phone) ---
# [Interface]
# Address = 10.8.0.2/24
# PrivateKey = <contents of client.key>
# DNS = 1.1.1.1
# [Peer]
# PublicKey = <contents of server.pub>
# Endpoint = VPS_PUBLIC_IP:51820
# AllowedIPs = 0.0.0.0/0        # full tunnel; ::/0 too for IPv6
# PersistentKeepalive = 25

验证它,以及诚实的权衡

Open the firewall for UDP 51820, bring up the client tunnel, and confirm your exit changed by checking curl https://api.ipify.org — it should show the VPS IP, not your home one. On the client, AllowedIPs = 0.0.0.0/0 is what makes it a full tunnel that carries every packet (add ::/0 to avoid an IPv6 leak); a narrower list makes it split tunnel. If throughput is poor, it is almost always MTU — see WireGuard MTU.

诚实的部分:自托管的WireGuard出口是一个单一的数据中心IP,您必须修补、监控并保持安全,因为它仅由您使用,因此与您有直接关联。这与共享IP VPN的匿名性正好相反。s4m运行一个托管的WireGuard和OpenVPN VPN,采用无日志、内存优先的设计,您与其他人共享出口——更适合融入——并且如果您特别想要一个私人IP,还有一个专用IP附加选项。DIY以获得控制;托管以获得匿名性和零操作。请参见WireGuard客户端指南。

Share this page
FAQ

问题,已解答

为什么我的WireGuard隧道连接但没有互联网?

几乎总是缺少NAT规则或IP转发。服务器需要net.ipv4.ip_forward=1和其WAN接口上的POSTROUTING MASQUERADE规则,以便客户端流量被转换到互联网。没有这两者,数据包到达服务器后会停止。

自托管的 VPN 比商业 VPN 更匿名吗?

通常更少。私人 VPS 出口仅由你使用,因此它可以直接与你关联。共享 IP 商业 VPN 将你的流量与许多用户混合。自托管提供控制;共享无日志 VPN 通过人群提供匿名性。

您的隧道,或我们的隧道

自托管WireGuard以完全控制一个出口,或使用托管的s4m WireGuard/OpenVPN VPN——无日志、优先使用RAM、共享出口以保持匿名——当你想要一个私人IP时使用专用IP。

人们通过搜索找到此页面

此页面回答的真实搜索短语 — 链接的短语打开详细覆盖它们的页面。