---
title: "How to set up a WireGuard VPN on your VPS for private access | StreetHosting"
description: "Set up a fast, lightweight WireGuard VPN on your VPS to reach panels and services without exposing them to the internet. Keep admin ports on a private network."
url: "https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps"
type: "page"
language: "en-US"
---

VPS · 3 min · Advanced

Published on Jun 17, 2026 · Updated on Jun 17, 2026

# WireGuard VPN on a VPS

Instead of exposing panels and databases to the internet, put everything behind a VPN. WireGuard is lightweight, fast and simple to configure, and it gives you secure private access to your VPS services.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking) [Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Getting started](https://streethosting.com.br/en/guides/topics/getting-started)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20set%20up%20a%20WireGuard%20VPN%20on%20your%20VPS%20for%20private%20access&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps "Share on LinkedIn") [](https://wa.me/?text=How%20to%20set%20up%20a%20WireGuard%20VPN%20on%20your%20VPS%20for%20private%20access%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fwireguard-vpn-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps.md)

In this guide 5 sections

* [Why a VPN](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#por-que-vpn)
* [Why WireGuard](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#wireguard)
* [Set it up](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#configurar)
* [Hide your services](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#esconder-servicos)
* [Best practices](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#boas-praticas)

Quick answer

With **WireGuard**, you create a lightweight VPN on your VPS and put panels, databases and admin services behind a private network. Generate the keys, configure the interface, give each device its own key and IP, and close the public ports in the firewall. Only people on the VPN can reach those services, which greatly reduces the attack surface.

## Why a VPN[](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#por-que-vpn)

Panels, databases and admin tools should not sit open on the internet. Every exposed port is an invitation to attack. A VPN creates a private corridor: you step into it and only then reach those services. It is a strong layer within your [server security checklist](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist).

## Why WireGuard[](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#wireguard)

WireGuard is lightweight, fast and much simpler to configure than older VPNs. Its lean codebase and good performance made it the favorite choice for private access to servers. In a few steps, you have a secure network between your devices and the VPS.

## Set it up[](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#configurar)

1. Install WireGuard and generate the server keys.
2. Define the IP range for the private network and the interface.
3. Create a key and a private IP for each device.
4. Connect a device and test access through the VPN network.

Combine the VPN with key-based login for SSH. See [passwordless SSH key login](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps) to close that port too.

## Hide your services[](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#esconder-servicos)

Only close public access to the services after confirming that the VPN works. Closing it before testing can lock you out of your own panels.

With the VPN active, adjust the [UFW firewall](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) so panels and databases are reachable only through the private network. The service disappears from the radar of anyone on the open internet.

## Best practices[](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#boas-praticas)

* One key per device
* Admin services only through the VPN
* Firewall closing public access
* VPN tested before closing the ports

A VPN is one of the most effective defenses you can add. To host private services with room to spare, check out [Ryzen VPS](https://streethosting.com.br/en/vps/ryzen) and [dedicated servers](https://streethosting.com.br/en/dedicated).

In this guide

* [Why a VPN](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#por-que-vpn)
* [Why WireGuard](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#wireguard)
* [Set it up](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#configurar)
* [Hide your services](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#esconder-servicos)
* [Best practices](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps#boas-praticas)

## Frequently asked questions

Why hide panels behind a VPN?

Because anything exposed to the internet is a target for attacks. With panels and databases behind a VPN, only people on the private network can reach those services, which greatly reduces the attack surface.

Why choose WireGuard?

It is lightweight, fast and simple to configure compared to older VPNs. The lean codebase makes auditing easier and performance is high, which made it a popular choice for private access to servers.

Does each device need its own key?

Yes, and that is an advantage. Each device has its own key and private IP, so you grant and revoke access individually. If a device is lost, just remove its key.

Does the VPN replace the firewall?

No. It adds another layer. You keep the firewall closing public access to the services and use the VPN as the only path to reach them. The two layers together make a solid defense.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen) [See dedicated servers Exclusive hardware in São Paulo with NVMe and Anti-DDoS.](https://streethosting.com.br/en/dedicated)

## Related guides

[VPS Beginner UFW on Ubuntu VPS: firewall rules without losing SSH UFW makes the Ubuntu firewall simpler, but one rule in the wrong order locks you out of your VPS. Learn how to enable it without losing SSH, open only what you need, deal with Docker, and get back in through the console if something goes wrong. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) [VPS Intermediate How to set up passwordless SSH key login on a VPS Key-based login is safer and easier than a password. You generate a key pair, copy the public key to the server, and log in without typing anything. Here is how, in a few steps. 3 min Read guide](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps) [Infrastructure Intermediate Linux server security checklist: from fresh install to hardened A freshly created server is far too open. This checklist puts the hardening steps in order, turning a default machine into a server that is hard to break into. 3 min Read guide](https://streethosting.com.br/en/guides/infrastructure/linux-server-security-checklist)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
