Skip to main content
Mini PC Lab logo
Mini PC LabMini PCs for Homelabs
tutorials

How to Set Up WireGuard VPN on a Mini PC 2026

By Max · May 2, 2026 · Updated August 6, 2026

This article contains affiliate links. If you purchase through our links, we may earn a commission at no extra cost to you. We only recommend products we’ve thoroughly researched and verified.

How to set up WireGuard VPN on a mini PC hero image

WireGuard gives you secure access to your home network from anywhere — Plex, Nextcloud, Home Assistant, Pi-hole, and every other self-hosted service becomes accessible as if you’re sitting on your home LAN. It’s faster than OpenVPN, simpler to configure, and uses less than 50MB RAM running as a Docker container on your mini PC.

What you need:

  • A mini PC running Ubuntu Server 24.04 LTS with Docker installed
  • A static IP or dynamic DNS hostname for your home internet connection
  • UDP port 51820 forwarded on your router to the mini PC

Recommended hardware:


Step 1: Check Your Network Setup

Get Your Public IP

# From the mini PC
curl ifconfig.me

Set Up Dynamic DNS If Your IP Changes

Most home internet connections have a dynamic public IP that changes periodically. Use a free DDNS service so your VPN always connects to the right address:

DuckDNS free, reliable:

  1. Go to duckdns.org → log in → create a subdomain e.g., yourhome.duckdns.org
  2. Run the update client on your mini PC:
# Create DuckDNS update script
mkdir -p ~/duckdns && nano ~/duckdns/duck.sh
#!/bin/bash
echo url="https://www.duckdns.org/update?domains=YOURDOMAIN&token=YOUR-TOKEN&ip=" | curl -k -o ~/duckdns/duck.log -K -
chmod +x ~/duckdns/duck.sh

# Run every 5 minutes via cron
crontab -e
# Add:
*/5 * * * * ~/duckdns/duck.sh

Enable Port Forwarding

On your router:

  1. Log in to router admin typically 192.168.1.1
  2. Find “Port Forwarding” or “NAT” settings
  3. Add rule: External UDP port 51820 → Internal IP of mini PC, UDP port 51820

Step 2: Deploy WireGuard with wg-easy

wg-easy is the simplest WireGuard management solution — it runs WireGuard in Docker and provides a web UI for adding/removing VPN clients and downloading configs.

# Create wg-easy configuration
mkdir -p ~/wg-easy && nano ~/wg-easy/docker-compose.yml
services:
  wg-easy:
    image: ghcr.io/wg-easy/wg-easy:latest
    container_name: wg-easy
    environment:
      - LANG=en
      - WG_HOST=yourhome.duckdns.org   # Your DDNS hostname or public IP
      - PASSWORD_HASH=$$2y$$10$$hash   # See password setup below
      - WG_PORT=51820
      - WG_DEFAULT_ADDRESS=10.8.0.x    # Client IP range
      - WG_DEFAULT_DNS=192.168.1.100   # Your mini PC's IP (for Pi-hole/AdGuard DNS)
      - WG_ALLOWED_IPS=192.168.1.0/24,10.8.0.0/24  # Access home network + VPN subnet
    volumes:
      - ~/.wg-easy:/etc/wireguard
    ports:
      - "51820:51820/udp"   # WireGuard port
      - "51821:51821/tcp"   # Web UI port
    cap_add:
      - NET_ADMIN
      - SYS_MODULE
    sysctls:
      - net.ipv4.ip_forward=1
      - net.ipv4.conf.all.src_valid_mark=1
    restart: unless-stopped

Generate password hash:

# Install bcrypt tool
docker run --rm -it ghcr.io/wg-easy/wg-easy wgpw 'your-admin-password'
# Copy the hash and paste into PASSWORD_HASH (replace $ with $$)

Start wg-easy:

cd ~/wg-easy
docker compose up -d

Access the web UI at http://192.168.1.100:51821


Step 3: Create Client Configurations

In the wg-easy web UI:

  1. Click ”+ New Client”
  2. Name it: phone, laptop, work-pc, etc.
  3. Download the config file or scan the QR code

For each device you want to connect:

  • Mobile iOS/Android: Scan the QR code with the WireGuard app
  • Desktop Windows/Mac/Linux: Download the .conf file and import into WireGuard

Step 4: Configure Client Apps

iOS / Android

  1. Install “WireGuard” from App Store / Google Play
  2. Tap ”+” → “Scan QR Code”
  3. Scan the QR from wg-easy web UI
  4. Toggle “VPN” on

Windows

  1. Download WireGuard from wireguard.com/install
  2. Open WireGuard → “Import tunnel s from file”
  3. Select the downloaded .conf file
  4. Click “Activate”

Linux

# Install WireGuard
sudo apt install wireguard

# Copy the client config
sudo cp client.conf /etc/wireguard/wg0.conf
sudo chmod 600 /etc/wireguard/wg0.conf

# Connect
sudo wg-quick up wg0

# Verify connection
sudo wg show

Step 5: Test the VPN Connection

Turn off your device’s Wi-Fi and connect via cellular or use a hotspot. Enable WireGuard.

# Verify your device is routing through VPN
curl ifconfig.me
# Should show your home IP, not your cellular IP

# Test access to home services
curl http://192.168.1.100:8123  # Home Assistant
curl http://192.168.1.100:32400  # Plex

Advanced: Full Tunnel vs Split Tunnel

Full Tunnel route all traffic through VPN:

# In client config AllowedIPs:
AllowedIPs = 0.0.0.0/0, ::/0

All internet traffic routes through your home connection. You get Pi-hole ad blocking everywhere. Slower — limited by your home upload speed.

Split Tunnel route only home network traffic through VPN:

# In client config AllowedIPs:
AllowedIPs = 192.168.1.0/24, 10.8.0.0/24

Only traffic to your home network routes through VPN. Direct internet traffic is unaffected. Faster — better for watching streaming services while also accessing home devices.

In wg-easy: set WG_ALLOWED_IPS=192.168.1.0/24,10.8.0.0/24 for split tunnel or WG_ALLOWED_IPS=0.0.0.0/0,::/0 for full tunnel.


Alternative: LinuxServer WireGuard Advanced

For users who prefer more control over WireGuard configuration without a web UI:

services:
  wireguard:
    image: lscr.io/linuxserver/wireguard:latest
    container_name: wireguard
    cap_add:
      - NET_ADMIN
      - SYS_MODULE
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=America/New_York
      - SERVERURL=yourhome.duckdns.org
      - SERVERPORT=51820
      - PEERS=phone,laptop,work  # Comma-separated client names
      - PEERDNS=192.168.1.100    # Use Pi-hole/AdGuard for DNS
      - INTERNAL_SUBNET=10.13.13.0/24
    volumes:
      - ~/.wireguard/config:/config
      - /lib/modules:/lib/modules
    ports:
      - 51820:51820/udp
    sysctls:
      - net.ipv4.conf.all.src_valid_mark=1
    restart: unless-stopped

Client configs are generated in ~/.wireguard/config/peer_*/ as .conf files and QR codes.


Troubleshooting

Can’t Connect from Outside

# Verify WireGuard is listening
sudo ss -tulnp | grep 51820

# Check port forwarding with external tool
# Visit portchecker.co and check port 51820

# Verify firewall allows UDP 51820
sudo ufw allow 51820/udp

Connected but Can’t Reach Home Devices

Check that IP forwarding is enabled on the host:

sysctl net.ipv4.ip_forward
# Should return: net.ipv4.ip_forward = 1

# Enable if not:
echo "net.ipv4.ip_forward=1" | sudo tee -a /etc/sysctl.conf
sudo sysctl -p

ISP CGNAT Port Forwarding Not Working

If your ISP uses carrier-grade NAT, your router doesn’t have a public IP — port forwarding is impossible. Solutions:

Option 1: Cloudflare Tunnel free: Cloudflare Tunnel creates an outbound connection from your server to Cloudflare — no port forwarding needed. Limited to TCP HTTP/HTTPS, not UDP, so not ideal for WireGuard itself, but works for Plex and other HTTP services.

Option 2: Cheap VPS as relay ~$4-5/month: Rent a small VPS Oracle Free Tier, Hetzner, or DigitalOcean, set up WireGuard on it, and connect both your home server and client devices to the VPS. Traffic routes: client → VPS → home server.


Performance Guide

WireGuard throughput on mini PC hardware AES-NI enabled:

CPUSingle-core throughputReal-world VPN speed
Intel N95~600 MbpsLimited by home upload
Intel N150~800 MbpsLimited by home upload
Intel i5-12450H~950+ MbpsLimited by home upload
AMD Ryzen 7 H255~950+ MbpsLimited by home upload

Home internet upload speed is almost always the bottleneck — not the CPU. If your home upload is 100 Mbps: you’ll get ~100 Mbps through WireGuard regardless of which mini PC you use.


Who Should Skip This Comparison

Frequently Asked Questions

Should I use WireGuard or Tailscale?

Tailscale is WireGuard with a coordination layer — it handles peer discovery, NAT traversal, and client configuration automatically, including through CGNAT. It’s simpler to set up but requires trusting Tailscale’s coordination servers. Self-hosted WireGuard keeps everything on your infrastructure. For beginners or CGNAT users: start with Tailscale. For full control: self-host WireGuard.

Can multiple devices connect simultaneously?

Yes. WireGuard supports many concurrent clients — each gets a unique private key and IP address. Performance scales linearly with concurrent connections but barely registers on N-series mini PC hardware.

Does WireGuard work when my IP changes?

If you use DDNS and set the DDNS hostname as WG_HOST, WireGuard clients reconnect automatically when your home IP changes. The DDNS update script keeps the hostname pointing to your current IP. WireGuard clients refresh DNS on each reconnect.

Can I run WireGuard alongside OPNsense on the EQ14?

Yes. On the EQ14 with Proxmox: run OPNsense in a VM and install the WireGuard plugin in OPNsense. This is more integrated than running WireGuard in Docker separately — OPNsense handles the firewall rules and routing automatically. The EQ14’s dual NICs make this particularly powerful: WAN on one NIC, LAN on the other, WireGuard clients appearing on the LAN subnet.

What’s the difference between WireGuard and OpenVPN for a home server?

WireGuard is faster 1-4× throughput, simpler less configuration, uses fewer resources <1% CPU vs 5-10% for OpenVPN at comparable throughput, and is considered more modern and secure. OpenVPN has better compatibility with corporate firewalls that block non-standard ports WireGuard requires UDP, which some firewalls block. For home use: WireGuard is the clear choice.

Can a mini PC run WireGuard VPN?

Yes. WireGuard uses minimal resources — under 50MB RAM and less than 1% CPU at idle on any modern mini PC. The Beelink MINI S12 or EQ14 handle WireGuard alongside Home Assistant, Pi-hole, and Docker services without measurable impact. AES-NI hardware acceleration in all Intel and AMD chips speeds up the AES-256 encryption used by WireGuard.

What is the best way to run WireGuard on a mini PC?

wg-easy is the recommended Docker image — it provides WireGuard with a web UI for managing client configurations, QR codes for mobile setup, and automatic port management. For headless setups: linuxserver/wireguard is a solid alternative. Both run as Docker containers and configure the kernel WireGuard module automatically.

Enable Port Forwarding

Standard WireGuard requires port forwarding on your router UDP port 51820 to reach the VPN server. If your ISP uses CGNAT carrier-grade NAT, port forwarding is not possible — use a Cloudflare Tunnel or a cheap VPS as a WireGuard relay instead. Check if port forwarding works by scanning your public IP from outside your network.

Can I use the mini PC VPN to access Plex from outside my home?

Yes. Connect to WireGuard on your phone or laptop from anywhere. Your device appears on your home network — access Plex at its local IP, browse Nextcloud files, check Home Assistant, and use Pi-hole DNS blocking on the go. This is often preferable to Plex’s relay servers, which limit quality.