WireGuardLab
Mesh Topology Designer

WireGuard Mesh Config Generator: wg0.conf for Every Peer

Choose a full mesh or hub and spoke, then select a node to generate its wg0.conf skeleton and AllowedIPs. Replace the key and endpoint placeholders before use. Transport presets provide a starting MTU to check against your path.

Network Parameters

4

Transport & MTU Tuning

Active WireGuard Tunnels
6
Direct Encrypted Links
Recommended WireGuard MTU
1420
1500 byte path minus 80
Encapsulation Overhead
60 Bytes
16B header + 16B Poly1305 tag + 8B UDP + 20B IPv4

AllowedIPs for each peer

Node 1: one host route per remote peer in this full mesh.

Peer blockAllowedIPs
Node 210.8.0.2/32
Node 310.8.0.3/32
Node 410.8.0.4/32

These routes cover the overlay. For LAN prefixes and hub forwarding, read AllowedIPs for full mesh vs hub and spoke.

/etc/wireguard/wg0.conf (Node 1)
[Interface]
# Node 1 - Local node
PrivateKey = <NODE_1_PRIVATE_KEY>
Address = 10.8.0.1/32
ListenPort = 51820
MTU = 1420

# Peer 2 Node
[Peer]
PublicKey = <NODE_2_PUBLIC_KEY>
Endpoint = wg-peer-2.example.com:51820
AllowedIPs = 10.8.0.2/32
PersistentKeepalive = 25

# Peer 3 Node
[Peer]
PublicKey = <NODE_3_PUBLIC_KEY>
Endpoint = wg-peer-3.example.com:51820
AllowedIPs = 10.8.0.3/32
PersistentKeepalive = 25

# Peer 4 Node
[Peer]
PublicKey = <NODE_4_PUBLIC_KEY>
Endpoint = wg-peer-4.example.com:51820
AllowedIPs = 10.8.0.4/32
PersistentKeepalive = 25
            

Technical Protocol Insights

  • Architecture: full mesh with 6 encrypted tunnels between 4 peers.
  • Recommended WireGuard MTU: 1420, from a 1500 byte path minus the 80 byte worst case.
  • PersistentKeepalive is on: an empty transport message every 25 seconds holds the NAT mapping open.
Fixed protocol facts
  • WireGuard adds 60 bytes over IPv4 and 80 over IPv6: a 16 byte transport header, a 16 byte Poly1305 tag, 8 bytes of UDP, and a 20 or 40 byte outer IP header.
  • wg-quick subtracts the worst case 80 bytes from the MTU of the route to the endpoint, which is why a 1500 byte path lands on 1420 whichever outer family it uses.
  • PersistentKeepalive = 25 keeps a stateful NAT mapping open from the inside, so set it on the NAT'd peer rather than the publicly reachable one.
  • Never configure the interface below 1280 when IPv6 runs inside the tunnel; RFC 8200 makes 1280 the minimum link MTU.

Sources: WireGuard Quick Start, wg configuration reference, and the MTU calculation guide.