Public Access
The documentation had kept up feature page by feature page and nowhere else. Now also: - the home page's App cards (notes of any size, pictures, sharing) and its note (the Shell, the VPN, the screenshot key); - the guide: VPN in the Status Bar and in Settings, the three keys that work everywhere, screenshots of the Shell, a picture, sharing, the VPN page and the help panel; - three how-tos: move files with your phone, set up the VPN, take a screenshot; where the files are and what things cost in memory; - the FAQ: screenshots, and what listens on the network; - the README's opening: what the firmware does today; - the glossary: Tunnel, Sharing, Screenshot; - every milestone's status line, with the version each thing shipped in. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
37 lines
2.1 KiB
Markdown
37 lines
2.1 KiB
Markdown
+++
|
|
title = "Set up the VPN"
|
|
description = "Put a WireGuard configuration on the device with your phone, import it, and check that the tunnel is up."
|
|
weight = 10
|
|
[extra]
|
|
tag = "VPN"
|
|
+++
|
|
|
|
You need a WireGuard server, and a **client configuration** made on it for the Cardputer, as you would make one for a phone: a `.conf` file.
|
|
|
|
1. Get the `.conf` onto the phone (or a computer on the same Wi-Fi), and name it **`wg0.conf`**.
|
|
2. On the Cardputer, open **Storage** and press <kbd>w</kbd>; open the page on the phone ([Move files with your phone](/howto/phone-files/)).
|
|
3. In the page, tap **New folder**, name it `vpn`, go into it, and **upload `wg0.conf`**.
|
|
4. On the Cardputer, press Back to stop sharing.
|
|
5. Open **Settings → VPN → Import /vpn/wg0.conf**. You should see "Imported", and a question: **delete the file**. Say yes: the configuration is now in the device, and the file still holds the private key in clear.
|
|
6. Switch **VPN** to On. `VPN` appears in the Status Bar, and turns bright once the server has answered, usually within seconds. The page says "It is up".
|
|
7. To have it start by itself, switch on **Start with Wi-Fi**.
|
|
|
|
## Check it
|
|
|
|
From another machine on the VPN, ping the Cardputer's tunnel address (the `Address` line of the file). Or on the device, in the [Shell](/guide/shell/): `vpn status`.
|
|
|
|
## If it stays dim
|
|
|
|
| The page says | Try |
|
|
|---|---|
|
|
| waiting for Wi-Fi | Connect to a network first |
|
|
| waiting for the clock | Give it a moment after Wi-Fi connects: the time comes from the network |
|
|
| looking up the server | The server's name doesn't resolve from this network |
|
|
| no answer yet | The server's address or port, a firewall on the way, or the keys: check the server's side has this client's public key |
|
|
|
|
## What goes through it
|
|
|
|
Everything, if the file says `AllowedIPs = 0.0.0.0/0`; otherwise only the VPN's own subnet. To reach your home network behind the server, you need the first. See [VPN](/guide/vpn/#what-goes-through-it).
|
|
|
|
**The upload in step 3 is not encrypted,** and the file holds a private key: do it on a network you trust, with a key made for this device.
|