WireGuard Config Generator
Generate matching WireGuard server and client configurations with correct AllowedIPs, MTU, keepalive and firewall rules, and understand the routing rule that makes AllowedIPs different from an access list.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
AllowedIPs does two jobs at once
AllowedIPs is the setting people misunderstand most, because it means different things in each direction. On the server it is an access control list: a packet arriving from a peer is dropped unless its source address is within that peer's AllowedIPs, which is how WireGuard binds an identity to an address range with no separate authentication step. On the client it is also a routing table: WireGuard installs a route for every prefix listed, so setting it to 0.0.0.0/0 sends all traffic through the tunnel while setting it to a single subnet sends only that.
Keys are generated on the device that will hold them
A private key should never travel. The correct procedure is to generate the key pair on each device, send only the public key to whoever assembles the configuration, and never write a private key into a file that leaves its machine. This tool therefore generates the configuration structure with placeholders rather than the keys themselves, because a private key produced in a browser tab has already been exposed to the browser environment.
PersistentKeepalive is only needed behind NAT
WireGuard is silent when there is nothing to send, which is a genuine advantage and a problem behind a NAT device whose mapping expires after a period of inactivity. A keepalive of twenty five seconds holds the mapping open so the far side can initiate. It is required on a client behind NAT that must be reachable, unnecessary on a server with a public address, and setting it everywhere wastes battery on mobile clients for no benefit.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What does AllowedIPs actually control?
Both routing and access control. Inbound, a packet from a peer is dropped unless its source falls within that peer’s AllowedIPs. Outbound, WireGuard routes traffic for those prefixes to that peer. The same setting therefore decides both what a peer may claim to be and what traffic reaches it.
Should I set AllowedIPs to 0.0.0.0/0?
On a client, only if you want all traffic through the tunnel. For split tunnelling, list just the networks that should traverse it. On the server, each peer should have only its own address, or the range it is a gateway for.
Why is my tunnel silent until I send traffic?
By design. WireGuard sends nothing when there is nothing to send, which is why it is efficient on battery. Behind NAT that means the mapping expires and the far side cannot initiate, which PersistentKeepalive of 25 seconds prevents.
What MTU should I use?
1420 over IPv4 and 1400 over IPv6, from a 1500 byte path. WireGuard adds 60 bytes of overhead over IPv4. If the underlying path is already reduced, such as PPPoE at 1492, subtract from that instead.
Is it safe to generate keys in a browser?
No, and this tool does not. A private key that has existed in a browser tab has been exposed to the browser environment including extensions. Generate keys on the device that will use them with wg genkey, and share only the public key.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Set your network, endpoint and peer count to generate the server and client configuration files.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.