Create a client VPN

Create a WireGuard client VPN from Networking, Client VPN.

Prerequisites

To create a client VPN

  1. Choose Networking, Client VPN, then create an instance.
  2. For Name, enter a DNS label (lowercase alphanumeric and hyphens, at most 30 characters).
  3. Choose an Availability zone and Server type for the gateway.
  4. For Address pool, enter a tunnel CIDR (default 10.8.0.0/24). Capacity is reduced by network, gateway, and broadcast addresses.
  5. For Listen port, keep 51820 or choose another UDP port.
  6. For Routing, choose full tunnel or split tunnel. For split tunnel, list comma-separated destination CIDRs.
  7. (Optional) Set a DNS server handed to clients.
  8. Choose Save.

Wait until Status is Ready before adding users.

Note The listen port is opened on the instance firewall. Clients must reach the public endpoint on that UDP port.

Next steps