Mesh Topology Designer
WireGuard Mesh Config Generator: wg0.conf for Every Peer
Choose a full mesh or hub and spoke, then select a node to generate its wg0.conf skeleton and AllowedIPs. Replace the key and endpoint placeholders before use. Transport presets provide a starting MTU to check against your path.
Network Parameters
4
Transport & MTU Tuning
Active WireGuard Tunnels
6
Direct Encrypted Links
Recommended WireGuard MTU
1420
1500 byte path minus 80
Encapsulation Overhead
60 Bytes
16B header + 16B Poly1305 tag + 8B UDP + 20B IPv4
AllowedIPs for each peer
Node 1: one host route per remote peer in this full mesh.
| Peer block | AllowedIPs |
|---|---|
| Node 2 | 10.8.0.2/32 |
| Node 3 | 10.8.0.3/32 |
| Node 4 | 10.8.0.4/32 |
These routes cover the overlay. For LAN prefixes and hub forwarding, read AllowedIPs for full mesh vs hub and spoke.
/etc/wireguard/wg0.conf (Node 1)
[Interface]
# Node 1 - Local node
PrivateKey = <NODE_1_PRIVATE_KEY>
Address = 10.8.0.1/32
ListenPort = 51820
MTU = 1420
# Peer 2 Node
[Peer]
PublicKey = <NODE_2_PUBLIC_KEY>
Endpoint = wg-peer-2.example.com:51820
AllowedIPs = 10.8.0.2/32
PersistentKeepalive = 25
# Peer 3 Node
[Peer]
PublicKey = <NODE_3_PUBLIC_KEY>
Endpoint = wg-peer-3.example.com:51820
AllowedIPs = 10.8.0.3/32
PersistentKeepalive = 25
# Peer 4 Node
[Peer]
PublicKey = <NODE_4_PUBLIC_KEY>
Endpoint = wg-peer-4.example.com:51820
AllowedIPs = 10.8.0.4/32
PersistentKeepalive = 25
Technical Protocol Insights
- Architecture: full mesh with 6 encrypted tunnels between 4 peers.
- Recommended WireGuard MTU: 1420, from a 1500 byte path minus the 80 byte worst case.
- PersistentKeepalive is on: an empty transport message every 25 seconds holds the NAT mapping open.
Fixed protocol facts
- WireGuard adds 60 bytes over IPv4 and 80 over IPv6: a 16 byte transport header, a 16 byte Poly1305 tag, 8 bytes of UDP, and a 20 or 40 byte outer IP header.
- wg-quick subtracts the worst case 80 bytes from the MTU of the route to the endpoint, which is why a 1500 byte path lands on 1420 whichever outer family it uses.
- PersistentKeepalive = 25 keeps a stateful NAT mapping open from the inside, so set it on the NAT'd peer rather than the publicly reachable one.
- Never configure the interface below 1280 when IPv6 runs inside the tunnel; RFC 8200 makes 1280 the minimum link MTU.
Sources: WireGuard Quick Start, wg configuration reference, and the MTU calculation guide.
Before you deploy this config
- WireGuard MTU calculator and fragmentation fix Where the 60 and 80 byte overhead comes from, how to measure your real path MTU, and when to clamp TCP MSS instead.
- Keys, AllowedIPs, and NAT traversal explained Why AllowedIPs is a routing table outbound and an access control list inbound, and what the handshake timers mean.
- WireGuard setup on Ubuntu: server and client Key generation, forwarding, NAT and firewall rules, and adding a peer without dropping the existing ones.
- WireGuard vs Tailscale: which one to run A full mesh needs N(N-1)/2 tunnels. When that config growth stops being worth it, an overlay takes over.