WireGuard Client Setup

AMTAB Systems that have an internet connection are normally connected to AMTAB’s WireGuard network, hosted on server-1.amtab.se. This allows the systems to be reached remotely over an encrypted tunnel.

Each customer has a dedicated subnet within 10.9.0.0/16, for example 10.9.2.0/24 or 10.9.3.0/24. Your systems are placed in your subnet, and it is isolated from all other customers. This guide describes how to connect a computer to your subnet so that you can reach your systems.

Before You Start

Request the following from AMTAB:

  • Your subnet, for example 10.9.2.0/24.

  • The address to use for your computer within that subnet.

  • The address of one of your systems, to test the connection against.

Client Install Guide

This guide is aimed at Windows users, but the principle is the same for MacOS, Linux, Android and iOS - though the pictures will be incorrect.

  1. Download, install and run the client from the official WireGuard website.

  2. Choose to create a new empty tunnel. A private/public key pair is automatically generated by the client, and the settings file is displayed. The private key is sensitive information and should never be shared with anyone.

    Create new empty tunnel
  3. Name the tunnel “amtab-server-1” or something similar.

  1. Below the PrivateKey field, add the following. Replace <x> with the third number of your subnet, and <n> with the last number of the address you received from AMTAB:

    # Your computer's address, received from AMTAB
    Address = 10.9.<x>.<n>/32
    
    [Peer]
    PublicKey = Huq88inFGiCZq9CYl/DqPCWxjvqZ5mlxOpXZRfAd60I=
    # Your subnet, received from AMTAB
    AllowedIPs = 10.9.<x>.0/24
    Endpoint = server-1.amtab.se:51821
    PersistentKeepalive = 25
    

    For example, if your subnet is 10.9.2.0/24 and your address is 10.9.2.100, use Address = 10.9.2.100/32 and AllowedIPs = 10.9.2.0/24.

    Tunnel configuration with peer settings
  1. Select the text in the “Public key” textbox, and copy it. Paste it into an email or message to the person who gave you your address. They need to approve your connection before it can function. While waiting, continue with the steps below.

  2. Press “Save”. This will configure your client to establish a tunnel for the networks listed in AllowedIPs.

  3. To activate the WireGuard tunnel, click the “Activate” button. Note that the connection must be approved before it can function. The tunnel will only affect traffic destined for AMTAB systems so it can be activated at all times, but may conflict with other networks in some configurations. If that happens, request assistance from the person who gave you your address.

    Activating the tunnel
  1. Test the connection by opening the address of the system you received from AMTAB in a web browser, for example https://10.9.<x>.10/. It’s safe to ignore the security warning.