Public Access
Network troubleshooting from the device itself, in the Shell and over both consoles. ping, nslookup, port and traceroute each run on a task of their own and print as they go, to the console that asked; one at a time, and `cancel` stops it. ifconfig and arp answer at once: the interfaces (Wi-Fi and the VPN), which is the default route, the DNS servers, the neighbours. nslookup asks a DNS server itself, so it can say which server answered and in how long, and ask another. A sized ping finds what a tunnel really carries. With a how-to, "When the network doesn't work", and the rest of the docs. tls, ntp and netstat from the issue's list are not in this. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
37 lines
2.2 KiB
Markdown
37 lines
2.2 KiB
Markdown
+++
|
|
title = "Set up the VPN"
|
|
description = "Put a WireGuard configuration on the device with your phone, import it, and check that the tunnel is up."
|
|
weight = 10
|
|
[extra]
|
|
tag = "VPN"
|
|
+++
|
|
|
|
You need a WireGuard server, and a **client configuration** made on it for the Cardputer, as you would make one for a phone: a `.conf` file.
|
|
|
|
1. Get the `.conf` onto the phone (or a computer on the same Wi-Fi), and name it **`wg0.conf`**.
|
|
2. On the Cardputer, open **Storage** and press <kbd>w</kbd>; open the page on the phone ([Move files with your phone](/howto/phone-files/)).
|
|
3. In the page, tap **New folder**, name it `vpn`, go into it, and **upload `wg0.conf`**.
|
|
4. On the Cardputer, press Back to stop sharing.
|
|
5. Open **Settings → VPN → Import /vpn/wg0.conf**. You should see "Imported", and a question: **delete the file**. Say yes: the configuration is now in the device, and the file still holds the private key in clear.
|
|
6. Switch **VPN** to On. `VPN` appears in the Status Bar, and turns bright once the server has answered, usually within seconds. The page says "It is up".
|
|
7. To have it start by itself, switch on **Start with Wi-Fi**.
|
|
|
|
## Check it
|
|
|
|
On the device, in the [Shell](/guide/shell/): `vpn status`, then `ifconfig` (a `vpn` line, up) and `ping` the server's tunnel address. Or from another machine on the VPN, ping the Cardputer's tunnel address (the `Address` line of the file). More in [When the network doesn't work](/howto/network-check/).
|
|
|
|
## If it stays dim
|
|
|
|
| The page says | Try |
|
|
|---|---|
|
|
| waiting for Wi-Fi | Connect to a network first |
|
|
| waiting for the clock | Give it a moment after Wi-Fi connects: the time comes from the network |
|
|
| looking up the server | The server's name doesn't resolve from this network |
|
|
| no answer yet | The server's address or port, a firewall on the way, or the keys: check the server's side has this client's public key |
|
|
|
|
## What goes through it
|
|
|
|
Everything, if the file says `AllowedIPs = 0.0.0.0/0`; otherwise only the VPN's own subnet. To reach your home network behind the server, you need the first. See [VPN](/guide/vpn/#what-goes-through-it).
|
|
|
|
**The upload in step 3 is not encrypted,** and the file holds a private key: do it on a network you trust, with a key made for this device.
|