Protocol reference

WireGuard

A compact IP tunnel using public keys and a defined cryptographic suite.

Three checks when reading a VPN or proxy protocol: identity and keys, data transfer, and traffic and DNS policy.
Check authentication, data transfer, and traffic/DNS policy separately. VPNs and proxies can cover different traffic; routing and DNS depend on the protocol and client.
Transport
UDP
Protocol reference
Tunnel protocol
Address scope
Current reference

How the connection works

A peer public key is associated with allowed tunnel addresses. AllowedIPs selects the peer for outgoing destinations and checks source addresses on authenticated incoming packets. Routes, DNS and account management remain separate configuration tasks.

Configuration checkpoints

  • Associate the correct public key with each peer. Never paste a real PrivateKey or PresharedKey into a public issue, screenshot or shared example.
  • Review AllowedIPs together with operating-system routes. For example, 10.0.0.0/24 selects that subnet; 0.0.0.0/0 and ::/0 describe the IPv4 and IPv6 default destinations separately.
  • Check the endpoint, UDP reachability and the need for PersistentKeepalive when a peer is behind NAT. Keepalive preserves a mapping; it does not change which traffic is routed.

Verify the traffic path

  • Check IPv4 and IPv6 routes separately. A route for one address family does not demonstrate coverage of the other.
  • Check the resolver used by the operating system and by applications that select their own DNS service. A public DNS lookup on this site does not test your device for DNS leaks.
  • Observe a controlled disconnect on your own device. Protocol support does not establish a client kill switch or application-specific routing policy.

Diagnose a connection problem

Separate endpoint reachability, authentication, route selection and DNS resolution. Record the client version and the exact error; change one setting at a time. A handshake with no working traffic often needs route or resolver investigation, while an authentication error needs credentials or certificate checks.

Scope and limitations

Read the protocol and the client configuration together. A successful handshake does not prove that every application, IPv6 route or DNS request uses the tunnel.

This page explains a mechanism and a verification approach. It contains no original speed, regional-access or leak measurements. Throughput depends on the implementation, device, path and server; a protocol name cannot identify a universal winner.