- Transport
- UDP
- Protocol reference
- Tunnel protocol
- Address scope
- Current reference
How the connection works
A peer public key is associated with allowed tunnel addresses. AllowedIPs selects the peer for outgoing destinations and checks source addresses on authenticated incoming packets. Routes, DNS and account management remain separate configuration tasks.
Configuration checkpoints
- Associate the correct public key with each peer. Never paste a real PrivateKey or PresharedKey into a public issue, screenshot or shared example.
- Review AllowedIPs together with operating-system routes. For example, 10.0.0.0/24 selects that subnet; 0.0.0.0/0 and ::/0 describe the IPv4 and IPv6 default destinations separately.
- Check the endpoint, UDP reachability and the need for PersistentKeepalive when a peer is behind NAT. Keepalive preserves a mapping; it does not change which traffic is routed.
Verify the traffic path
- Check IPv4 and IPv6 routes separately. A route for one address family does not demonstrate coverage of the other.
- Check the resolver used by the operating system and by applications that select their own DNS service. A public DNS lookup on this site does not test your device for DNS leaks.
- Observe a controlled disconnect on your own device. Protocol support does not establish a client kill switch or application-specific routing policy.
Diagnose a connection problem
Separate endpoint reachability, authentication, route selection and DNS resolution. Record the client version and the exact error; change one setting at a time. A handshake with no working traffic often needs route or resolver investigation, while an authentication error needs credentials or certificate checks.
Scope and limitations
Read the protocol and the client configuration together. A successful handshake does not prove that every application, IPv6 route or DNS request uses the tunnel.
This page explains a mechanism and a verification approach. It contains no original speed, regional-access or leak measurements. Throughput depends on the implementation, device, path and server; a protocol name cannot identify a universal winner.