Files
roro9stack/site/content/howto/vpn.md
T
twislaandClaude Opus 5.5 ed7abdcaf5
CI / build (pull_request) Successful in 1m38s
Site / build (pull_request) Successful in 11s
Shell: ping, nslookup, port, traceroute, ifconfig and arp (#90)
Network troubleshooting from the device itself, in the Shell and over both
consoles. ping, nslookup, port and traceroute each run on a task of their
own and print as they go, to the console that asked; one at a time, and
`cancel` stops it. ifconfig and arp answer at once: the interfaces (Wi-Fi
and the VPN), which is the default route, the DNS servers, the neighbours.

nslookup asks a DNS server itself, so it can say which server answered and
in how long, and ask another. A sized ping finds what a tunnel really
carries.

With a how-to, "When the network doesn't work", and the rest of the docs.
tls, ntp and netstat from the issue's list are not in this.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-08 02:29:04 +02:00

37 lines
2.2 KiB
Markdown

+++
title = "Set up the VPN"
description = "Put a WireGuard configuration on the device with your phone, import it, and check that the tunnel is up."
weight = 10
[extra]
tag = "VPN"
+++
You need a WireGuard server, and a **client configuration** made on it for the Cardputer, as you would make one for a phone: a `.conf` file.
1. Get the `.conf` onto the phone (or a computer on the same Wi-Fi), and name it **`wg0.conf`**.
2. On the Cardputer, open **Storage** and press <kbd>w</kbd>; open the page on the phone ([Move files with your phone](/howto/phone-files/)).
3. In the page, tap **New folder**, name it `vpn`, go into it, and **upload `wg0.conf`**.
4. On the Cardputer, press Back to stop sharing.
5. Open **Settings → VPN → Import /vpn/wg0.conf**. You should see "Imported", and a question: **delete the file**. Say yes: the configuration is now in the device, and the file still holds the private key in clear.
6. Switch **VPN** to On. `VPN` appears in the Status Bar, and turns bright once the server has answered, usually within seconds. The page says "It is up".
7. To have it start by itself, switch on **Start with Wi-Fi**.
## Check it
On the device, in the [Shell](/guide/shell/): `vpn status`, then `ifconfig` (a `vpn` line, up) and `ping` the server's tunnel address. Or from another machine on the VPN, ping the Cardputer's tunnel address (the `Address` line of the file). More in [When the network doesn't work](/howto/network-check/).
## If it stays dim
| The page says | Try |
|---|---|
| waiting for Wi-Fi | Connect to a network first |
| waiting for the clock | Give it a moment after Wi-Fi connects: the time comes from the network |
| looking up the server | The server's name doesn't resolve from this network |
| no answer yet | The server's address or port, a firewall on the way, or the keys: check the server's side has this client's public key |
## What goes through it
Everything, if the file says `AllowedIPs = 0.0.0.0/0`; otherwise only the VPN's own subnet. To reach your home network behind the server, you need the first. See [VPN](/guide/vpn/#what-goes-through-it).
**The upload in step 3 is not encrypted,** and the file holds a private key: do it on a network you trust, with a key made for this device.