Skip to content
Back to skills

Wireguard

ASecurity

Configure WireGuard VPN tunnels with secure routing and key management.

  • 17 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 6, 2026
code-qualitygodebuggingsecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill wireguard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Wireguard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Wireguard
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-wireguard/badge)](https://www.skillsdirectory.com/skills/clawic-wireguard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: WireGuard
slug: wireguard
version: 1.0.0
description: Configure WireGuard VPN tunnels with secure routing and key management.
homepage: https://clawic.com/skills/wireguard
metadata:
  clawdbot:
    emoji: πŸ”
    requires:
      bins:
      - wg
    os:
    - linux
    - darwin
    - win32
    displayName: WireGuard
---

## AllowedIPs Traps (Most Common Mistakes)
- `AllowedIPs` means different things on each side β€” server: what peer CAN send; client: what to ROUTE through tunnel
- `0.0.0.0/0` routes ALL traffic including tunnel endpoint β€” breaks connectivity, must exclude server's public IP first
- Overlapping AllowedIPs between peers = undefined routing β€” each IP range must belong to exactly one peer
- Wrong mask silently breaks routing β€” `/32` for single host, `/24` for subnet, verify carefully

## Connection Failures
- No handshake = wrong public key, firewall blocking UDP, or wrong endpoint β€” check all three, not just one
- One-way traffic = AllowedIPs misconfigured β€” packets go out but replies don't route back
- Missing `PersistentKeepalive = 25` breaks NAT traversal β€” peer behind NAT unreachable after ~2 minutes
- Config file permissions must be 600 β€” wg-quick silently refuses to start with loose permissions

## DNS Leaks
- Without `DNS =` in client config, DNS queries bypass tunnel β€” leaks real IP to DNS provider
- Full tunnel (`0.0.0.0/0`) without DNS config = false sense of security β€” traffic tunneled but DNS exposed

## Routing Setup
- IP forwarding disabled by default on Linux β€” tunnel works but packets don't route between interfaces
- NAT required for internet access through tunnel β€” without masquerade, return packets don't find their way
- Firewall must allow UDP on ListenPort β€” WireGuard is UDP only, no TCP fallback exists

## Key Security
- Private key file permissions matter β€” world-readable key is compromised, set 600 immediately after generation
- Never transmit private keys β€” generate on each machine, exchange only public keys
- Config files contain private keys β€” treat wg0.conf as secret, not just privatekey file

## Live Changes
- Adding peers requires interface reload on most setups β€” or use `wg set` for live changes without dropping connections
- `wg syncconf` applies changes without restart β€” but config file format differs from wg.conf (use `wg-quick strip`)

## Debugging
- `wg show` displays handshake timestamps β€” stale handshake (>2 min) means connection dead despite interface up
- Handshake happens on first packet β€” no traffic = no handshake attempt, ping to test

Files in this skill

  • SKILL.md2.5 KB
  • _meta.json170 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…