Create a client VPN
Create a WireGuard client VPN from Networking, Client VPN.
Prerequisites
- BYOA secrets configured for your account
- An enabled availability zone
To create a client VPN
- Choose Networking, Client VPN, then create an instance.
- For Name, enter a DNS label (lowercase alphanumeric and hyphens, at most 30 characters).
- Choose an Availability zone and Server type for the gateway.
- For Address pool, enter a tunnel CIDR (default
10.8.0.0/24). Capacity is reduced by network, gateway, and broadcast addresses. - For Listen port, keep
51820or choose another UDP port. - For Routing, choose full tunnel or split tunnel. For split tunnel, list comma-separated destination CIDRs.
- (Optional) Set a DNS server handed to clients.
- Choose Save.
Wait until Status is Ready before adding users.
Note
The listen port is opened on the instance firewall. Clients must reach the public endpoint on that UDP port.