WireGuard with Linux
This tutorial shows how to configure the ISP side of the WireGuard VPN on a Linux server, after having created the VPN in Cpehub.
Prerequisites
Check off items as you confirm them — this is just a visual aid, so reloading the page unchecks everything again.
- The VPN has already been created in Cpehub (you have the peer data: Cpehub's public key, endpoint, IPs).
- A Linux server with access to the ISP's internal networks (the ones Cpehub needs to reach).
- Permission to install packages and create network interfaces.
1. Install WireGuard
# Debian / Ubuntu
sudo apt update && sudo apt install -y wireguard
# RHEL / Rocky / AlmaLinux
sudo dnf install -y wireguard-tools
2. Generate your side's key pair
wg genkey | tee privatekey | wg pubkey > publickey
- The contents of
publickeymust be entered in the VPN registration in Cpehub (ISP side). - The
privatekeystays only on your server.
3. Create the configuration file
Create /etc/wireguard/wg-cpehub.conf:
[Interface]
# Private key generated in step 2
PrivateKey = <YOUR_PRIVATE_KEY>
# This end's IP inside the tunnel (provided by Cpehub)
Address = <ISP_TUNNEL_IP>/32
[Peer]
# Cpehub's public key (shown when creating the VPN)
PublicKey = <CPEHUB_PUBLIC_KEY>
# Cpehub's endpoint (host:port)
Endpoint = <CPEHUB_ENDPOINT>:<PORT>
# Networks that will be routed through the tunnel
AllowedIPs = <CPEHUB_NETWORK>/32
# Keeps the tunnel alive through NAT/firewall
PersistentKeepalive = 25
The values between <...> come from the VPN registration in Cpehub and from step 2. Adjust AllowedIPs according to the networks that need to travel through the tunnel.
4. Bring up the interface
sudo wg-quick up wg-cpehub
# enable on boot
sudo systemctl enable wg-quick@wg-cpehub
To bring it down: sudo wg-quick down wg-cpehub.
5. Verify
sudo wg show
You should see the Cpehub peer with a recent latest handshake and transfer traffic increasing.
6. Routing to internal networks
For Cpehub to reach your OLTs, the Linux server needs to forward the tunnel traffic to the internal network:
# enable IP forwarding
echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/99-wg.conf
sudo sysctl --system
Also make sure the Remote Networks entered in the VPN registration in Cpehub include your OLTs' subnets.
Testing
In Cpehub, the VPN shows the connectivity status (using the Test Remote IP you entered when creating the VPN). If it's online, it's working.
Common issues
| Symptom | Likely cause | Solution |
|---|---|---|
| No handshake | Public key mismatch or wrong endpoint/port | Double-check keys and Endpoint |
| Handshake OK but can't ping the OLT | Missing route / ip_forward / AllowedIPs | Enable ip_forward and adjust routes and AllowedIPs |
| Drops after a while | NAT closing the session | Use PersistentKeepalive = 25 |