← How-Tos
raspberry-pi Jul 3, 2026 ◑ 1 views ◯ 1 min read

Pi as a VPN Server (WireGuard/PiVPN)

vpnwireguardpivpnsecurityraspberry pi

Why WireGuard Over OpenVPN

WireGuard is simpler, faster, and has a much smaller attack surface than OpenVPN — modern crypto by default, no config sprawl. Unless you have a specific reason to need OpenVPN (some corporate/legacy compatibility requirement), WireGuard is the right default in 2026.

Install via PiVPN

PiVPN wraps the whole setup (WireGuard install, key generation, client config generation) into one guided installer:

curl -L https://install.pivpn.io | bash

Walk through the prompts: pick WireGuard as the VPN type, confirm your Pi's static local IP, and either use your public IP directly or set up a dynamic DNS hostname if your ISP doesn't give you a static IP (most residential connections don't).

Router Port Forwarding

Forward UDP port 51820 (WireGuard's default) from your router to the Pi's local IP. This is the only port you need open — much smaller footprint than OpenVPN's typical TCP setup.

Adding Clients

pivpn add

This generates a client config file and a QR code — scan it directly in the WireGuard mobile app for instant setup, no manual config editing needed.

What You Get

Security Notes