{"id":19,"date":"2025-05-23T12:46:32","date_gmt":"2025-05-23T10:46:32","guid":{"rendered":"https:\/\/linuxundich.de\/en\/?p=19"},"modified":"2026-10-03T16:58:30","modified_gmt":"2026-10-03T14:58:30","slug":"setting-up-a-wireguard-vpn-between-a-fritzbox-and-linux","status":"publish","type":"post","link":"https:\/\/linuxundich.de\/en\/gnu-linux\/setting-up-a-wireguard-vpn-between-a-fritzbox-and-linux\/","title":{"rendered":"Setting up a WireGuard VPN between a Fritzbox and Linux"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Now that a new <a href=\"https:\/\/linuxundich.de\/hardware\/umzug-avm-fritzbox-5690-pro\/\">Fritzbox 5690 Pro<\/a> is sitting in my hallway, I can finally try out the (not really so) new WireGuard VPN of the <a href=\"https:\/\/linuxundich.de\/tag\/fritzbox\/\" data-type=\"link\" data-id=\"https:\/\/linuxundich.de\/tag\/fritzbox\/\">Fritzbox<\/a>. The VPN protocol itself isn&#8217;t new to me, since you can easily set it up with <a href=\"https:\/\/github.com\/wg-easy\/wg-easy\">wg-easy<\/a> and similar tools. Still, I find it handy when a feature like this is built right into the router and doesn&#8217;t have to run on a separate server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That way, access to your own network stays possible even on the day the server doesn&#8217;t work the way it should. If something is wrong with the box itself and the internet connection drops out completely, everything is usually lost anyway. On top of that, you need neither port forwarding nor an extra DynDNS service in this case, because AVM takes care of that with its <a href=\"https:\/\/fritz.com\/pages\/myfritz-net-hilfe\">MyFritz service<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Setting up WireGuard on the Fritzbox<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You set this up in the Fritzbox under <em>Internet<\/em> \u00bb <em>Permit Access<\/em> (<em>Freigaben<\/em>) on the <em>VPN (WireGuard)<\/em> tab. Click <em>Add Connection<\/em> and then choose <em>Connect single device<\/em>. You can name the connection whatever you like. Usually it&#8217;s the name of the client machine or of the person who will use the VPN. At the end, you have to confirm the new connection, for example by phone, by pressing a button on the box, or in the Fritz app.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Fritzbox then shows you a page with a QR code. Scan it with your smartphone to import the connection straight into the official <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.wireguard.android\">WireGuard app<\/a> for Android. Alternatively, you can use the open-source app <a href=\"https:\/\/web.archive.org\/web\/20250720165257\/https:\/\/f-droid.org\/de\/packages\/com.zaneschepke.wireguardautotunnel\/\">WG Tunnel<\/a>, which offers a lot more features than the \u201cofficial\u201d WireGuard client for Android. Personally, I use WG Tunnel, which I installed via F-Droid.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WireGuard configuration in NetworkManager<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For Linux (and desktop PCs in general), the Fritzbox lets you download the configuration. Click the button and save the file to your hard drive. By default, the file is saved as <code>wg_config.conf<\/code> in the <code>Downloads<\/code> folder. The name matters a bit, because some WireGuard clients automatically use it to name the interface.<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac1771006570&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac1771006570\" class=\"wp-block-image wp-lightbox-container\"><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/linuxundich.de\/wp-content\/uploads\/2025\/05\/fritzbox-wireguard_01-1280x856.webp\" alt=\"The Fritzbox generates the configuration automatically. All you have to do is download it or use the QR code. After that, the VPN is ready to use right away.\" style=\"width:100%\"\/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">The Fritzbox generates the configuration automatically. All you have to do is download it or use the QR code. After that, the VPN is ready to use right away.<\/figcaption><\/figure>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac17710068aa&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac17710068aa\" class=\"wp-block-image wp-lightbox-container\"><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/linuxundich.de\/wp-content\/uploads\/2025\/05\/fritzbox-wireguard_02-1280x856.webp\" alt=\"Choose the single device option to set up a connection between a mobile device or laptop and your home network. Site-to-site needs different settings.\" style=\"width:100%\"\/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Choose the single device option to set up a connection between a mobile device or laptop and your home network. Site-to-site needs different settings.<\/figcaption><\/figure>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac1771006bea&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac1771006bea\" class=\"wp-block-image wp-lightbox-container\"><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/linuxundich.de\/wp-content\/uploads\/2025\/05\/fritzbox-wireguard_03-1280x856.webp\" alt=\"The QR code is ideal for smartphones. On Linux, though, it's usually more convenient to work with the exported configuration file, which is easy to import into NetworkManager.\" style=\"width:100%\"\/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">The QR code is ideal for smartphones. On Linux, though, it&#8217;s usually more convenient to work with the exported configuration file, which is easy to import into NetworkManager.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You can import it directly through NetworkManager on the desktop or from the command line. On <a href=\"https:\/\/linuxundich.de\/tag\/gnome\/\" data-type=\"post_tag\" data-id=\"1734\">GNOME<\/a>, open <em>Settings<\/em>, go to <em>Network<\/em>, click the plus icon and choose <em>Import from file \u2026<\/em> [CHECK: label]. Then select the file <code>wg_config.conf<\/code> and import it. You can rename the connection however you like in the settings afterwards, but I recommend setting the interface name to <code>wg0<\/code>.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$ &lt;strong&gt;nmcli connection import type wireguard file ~\/Downloads\/wg_config.conf&lt;\/strong&gt;\nVerbindung \u00bbwg_config\u00ab (39724859-b102-4446-bdb2-1ec60f501360) erfolgreich hinzugef\u00fcgt.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s it. You can now activate the VPN directly from the Quick Settings in GNOME. Other desktop environments like KDE offer similar options as well. If you want to check whether the connection is up, install the <a href=\"https:\/\/extensions.gnome.org\/extension\/2983\/ip-finder\/\">IP Finder<\/a> extension on GNOME. It shows you your public IP address along with a country flag. As soon as the flag of your home country shows up instead of the one for where you currently are (for example, abroad on vacation), the VPN is up and running.<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac1771007055&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac1771007055\" class=\"wp-block-image wp-lightbox-container\"><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/linuxundich.de\/wp-content\/uploads\/2025\/05\/networkmanager-wireguard_01-1280x856.webp\" alt=\"The GNOME interface lets you import VPN configurations in just a few clicks. That makes the tunnel ready to use in no time, and without a terminal.\" style=\"width:100%\"\/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">The GNOME interface lets you import VPN configurations in just a few clicks. That makes the tunnel ready to use in no time, and without a terminal.<\/figcaption><\/figure>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac1771007348&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac1771007348\" class=\"wp-block-image wp-lightbox-container\"><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/linuxundich.de\/wp-content\/uploads\/2025\/05\/networkmanager-wireguard_02-1280x856.webp\" alt=\"After the import, you can still change the name of the connection. The interface can be renamed too, for example to the classic wg0.\" style=\"width:100%\"\/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">After the import, you can still change the name of the connection. The interface can be renamed too, for example to the classic wg0.<\/figcaption><\/figure>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac1771007636&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac1771007636\" class=\"wp-block-image wp-lightbox-container\"><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/linuxundich.de\/wp-content\/uploads\/2025\/05\/networkmanager-wireguard_03-1280x822.webp\" alt=\"Once the configuration is imported, you can switch on the VPN connection at any time from the quick settings. That keeps your system connected to your home network whenever you need it.\" style=\"width:100%\"\/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Once the configuration is imported, you can switch on the VPN connection at any time from the quick settings. That keeps your system connected to your home network whenever you need it.<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>A new Fritzbox brings official WireGuard support for the first time. That makes VPN access to your home network under Linux especially straightforward. Modern distributions usually ship the necessary tools out of the box.<\/p>\n","protected":false},"author":2,"featured_media":18,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"lui_source_id":45046,"lui_source_hash":"153311b41d9a8bb88137bef0e498282c5b7db3b8a132656bb50f3b9d90d78ae4","lui_source_translated":"2026-10-03","lui_source_reviewed":true,"lui_via_url":"","lui_via_label":"","lui_source_url":"","lui_source_label":"","footnotes":""},"categories":[2],"tags":[],"class_list":["post-19","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gnu-linux"],"_links":{"self":[{"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/posts\/19","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/comments?post=19"}],"version-history":[{"count":1,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/posts\/19\/revisions"}],"predecessor-version":[{"id":44,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/posts\/19\/revisions\/44"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/media\/18"}],"wp:attachment":[{"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/media?parent=19"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/categories?post=19"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/linuxundich.de\/en\/wp-json\/wp\/v2\/tags?post=19"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}