WireGuard VPS HostingYour Own Private VPN Server
Run a private VPN on a server only you control. We install WireGuard on a hardened KVM VPS, set up IP forwarding and firewall rules, and create client configs for the devices you list, so laptops, phones and offices connect over an encrypted tunnel.
Full root & SSH NVMe storage Daily backups Anti-DDoS 99.9% uptime SLA 11 locations
-
Static IPv4 and IPv6
A fixed exit address you can allow-list.
-
Anti-DDoS included
Always-on mitigation in front of your VPN.
-
Root and SSH access
Add peers, routes and rules yourself.
-
Reserved vCores
Encryption runs on cores that are yours.
Why Run Your Own VPN on a VPS
Commercial VPN apps share exit addresses with thousands of users. A WireGuard server on your own VPS gives you a private, static address and full control over who connects.
-
A static IP you can allow-list
Lock admin panels, databases and SSH on your other servers to the VPN's fixed IPv4 or IPv6 address.
-
Private access for your team
Connect staff laptops and phones to internal tools without exposing those tools to the internet.
-
Modern, fast cryptography
WireGuard runs in the Linux kernel with a small codebase and modern ciphers, and reconnects quickly when devices change networks.
-
Connect sites and servers
Link offices, home labs or servers in different locations with site-to-site tunnels.
How a WireGuard Server Works
One UDP port, one tunnel interface, and firewall rules deciding where each peer may go.
Encrypted UDP from your devices
-
Network
UDP port 51820
The only VPN port open in the firewall; WireGuard does not answer unauthenticated packets.
-
Tunnel
wg0 interface
Each peer has its own key pair and an address inside the VPN subnet.
-
Routing
IP forwarding + NAT
Lets peers reach the internet or your private networks through the server.
-
Firewall
UFW rules
Decide what peers may reach: everything, or only specific servers.
-
OS
Linux kernel
WireGuard is built into the kernel on current Ubuntu and Debian.
Worth knowing
- Every device gets its own key pair; revoke a device by removing its peer.
- AllowedIPs on the client chooses full tunnel (all traffic) or split tunnel (private ranges only).
- Set PersistentKeepalive on clients behind NAT so the tunnel stays up.
- Traffic through the VPN counts toward the monthly allowance in Mumbai, Singapore and Sydney.
What You Can Use It For
-
Secure remote work
Staff reach internal apps and file shares from anywhere.
-
Admin access to servers
SSH, database and dashboard ports reachable only over the VPN.
-
A fixed IP for allow-lists
Payment gateways, bank portals and SaaS admin panels that accept known IPs only.
-
Safer public Wi-Fi
Encrypt traffic from laptops and phones on untrusted networks.
-
Site-to-site links
Connect offices, home labs or servers in different locations.
-
Testing from another region
Check how your site behaves from Europe, Asia-Pacific or Canada.
VPS Plans for WireGuard
WireGuard needs very little CPU or RAM. Choose the plan by port speed and, in Asia-Pacific locations, by monthly traffic allowance.
VPS-1
Small websites, APIs, bots and development servers.
- 2 vCores
- 4 GB RAM
- 40 GB NVMe
- 500 Mbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
VPS-2
Production apps, WordPress and online stores.
- 4 vCores
- 8 GB RAM
- 75 GB NVMe
- 1 Gbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
VPS-3
Busy stores, SaaS products and several projects.
- 6 vCores
- 12 GB RAM
- 100 GB NVMe
- 2 Gbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
VPS-4
High-traffic apps, large databases and agencies.
- 8 vCores
- 24 GB RAM
- 200 GB NVMe
- 3 Gbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
* Unlimited traffic in Europe and North America. In Mumbai, Singapore and Sydney a monthly allowance applies (VPS-1 500 GB, VPS-2/VPS-3 1 TB, VPS-4 3 TB), then speed is limited to 10 Mbps until the next month.
Which Plan for Your VPN
Throughput and traffic matter more than RAM. VPN traffic counts toward the allowance in Mumbai, Singapore and Sydney.
| Workload | Start with | Why |
|---|---|---|
| Personal VPN or a small team | VPS-1 2 vCores · 4 GB RAM | 500 Mbps port; 500 GB a month in Asia-Pacific locations. |
| Team of 10 to 50 people | VPS-2 4 vCores · 8 GB RAM | 1 Gbps port; 1 TB a month in Asia-Pacific locations. |
| Busy team or site-to-site links | VPS-3 6 vCores · 12 GB RAM | 2 Gbps port for heavier traffic. |
| VPN plus other services | VPS-4 8 vCores · 24 GB RAM | 3 Gbps port; 3 TB a month in Asia-Pacific locations. |
A starting point, not a limit: every plan upgrades in place, keeping your data, IP address and configuration.
A Commercial VPN App or Your Own WireGuard Server?
Commercial VPNs give you many countries and no setup. Your own server gives you a private address and control over who connects.
| Feature | Commercial VPN service | WireGuard VPS |
|---|---|---|
| Exit IP address | Shared with many users | Dedicated to you |
| Who can connect | Anyone with an account | Only peers you add |
| Access to your private servers | No | Yes, through the tunnel |
| Locations | Many countries in one app | One server per location you choose (11 available) |
| Logs and data | The provider's policy | Your server, your rules |
| Server administration | Handled by the provider | Yours, after our free setup |
| See Plans |
Adding a Device to Your VPN
Each new laptop or phone gets its own key pair and an address in the VPN subnet.
-
Generate a key pair
For the new device; keep the private key on that device only.
-
Add the peer
Give it the next free address and save the config.
-
Hand over the client config
Show it as a QR code for the mobile app.
-
Check the connection
Shows each peer's last handshake and traffic.
# 1. Generate a key pair
wg genkey | tee laptop.key | wg pubkey > laptop.pub
# 2. Add the peer
sudo wg set wg0 peer "$(cat laptop.pub)" allowed-ips 10.8.0.5/32
sudo wg-quick save wg0
# 3. Hand over the client config
qrencode -t ansiutf8 < laptop.conf
# 4. Check the connection
sudo wg show
Example commands; adjust names, paths and versions to your project. Deploying and maintaining your application is yours to do (or ask us for a quote).
Installed and Secured Before You Log In
The VPS is unmanaged: after handover the server is yours to run. Before that, our engineers do the first setup once, free, so you start from a hardened server with WireGuard in place.
-
Choose a plan and location
Pick the resources you need and the datacentre closest to your users.
-
Tell us your WireGuard setup
Versions, database and domain: at order or right after.
-
We install and secure it
Server hardened, WireGuard installed and tested, HTTPS on your domain.
-
You take over with root
SSH access to a working server, ready for your code and data.
Your VPN server
- WireGuard with a server key pair and a private VPN subnet
- IP forwarding and NAT for full-tunnel use
- Firewall rules for UDP 51820 and SSH
- Client configs, with QR codes, for the devices you list
- IPv6 inside the tunnel on request
Yours to run after handover
- Ongoing server administration
- Application maintenance and updates
- Debugging your code
- Migrating existing sites or data
Not included in the free setup, but we can quote for it. No control panel by default: CloudPanel, HestiaCP or Virtualmin on request at no cost; cPanel and Plesk need their own licence.
Platform Specs and Locations
The same KVM platform on every plan; only the CPU, RAM, storage and port speed change.
| Virtualisation | KVM with reserved vCores and RAM |
|---|---|
| Storage | NVMe SSD on every plan |
| Network | Dedicated IPv4 and IPv6, 500 Mbps to 3 Gbps per plan |
| Operating systems | Ubuntu 26.04, 24.04 and 22.04 LTS · Debian 13, 12 and 11 · AlmaLinux · Rocky Linux · Fedora · FreeBSD |
| Access | Full root over SSH, key-based login |
| Backups | Automatic daily backup of the previous 24 hours; snapshots and longer retention on request |
| Protection | Always-on anti-DDoS mitigation |
| Availability | 99.9% uptime SLA |
Secured before we hand it over
- Non-root sudo user created for daily work
- SSH key login, password login for root disabled
- Firewall (UFW) open only for the ports you use
- Fail2ban blocking repeated login attempts
- Automatic security updates enabled
- Free Let's Encrypt SSL on your domain
- Timezone, swap and hostname configured
Asia-Pacific
- Mumbai
- Singapore
- Sydney
Europe
- London
- Limburg
- Roubaix
- Gravelines
- Strasbourg
- Milan
- Warsaw
North America
- Beauharnois
Availability per location changes with demand; we confirm your location before setup. In Mumbai, Singapore and Sydney each plan includes a monthly traffic allowance (VPS-1 500 GB, VPS-2 and VPS-3 1 TB, VPS-4 3 TB); beyond it, speed is limited to 10 Mbps until the next month.
Who a WireGuard VPS Suits
-
Small businesses
Remote staff reaching internal tools securely.
-
Developers and admins
Private access to servers, databases and dashboards.
-
Privacy-minded individuals
Your own encrypted exit point instead of a shared VPN service.
Security and Performance for WireGuard
Security
- Keep private keys on the devices that use them, and never share one key between devices.
- Remove peers for lost or retired devices straight away.
- Limit what peers can reach with firewall rules if not everyone needs everything.
- You are responsible for traffic leaving through your server; see our Acceptable Use Policy.
Performance
- Keep the MTU at 1420 or lower to avoid fragmentation on some networks.
- Choose the location closest to your users to keep latency low.
- Use split tunnelling when users only need private resources.
- Watch monthly traffic in Asia-Pacific locations, where an allowance applies.
Questions Before You Deploy
Not covered here? Ask an engineer before you order.
Run Your Own Private VPN
Choose a plan and a location, list your devices, and we hand over WireGuard with client configs ready to import.