Files
roro9stack/site/content/howto/vpn.md
T
twislaandClaude Opus 5.5 0c52613b72
CI / build (pull_request) Successful in 2m22s
Site / build (pull_request) Successful in 10s
Settings: its rows in five groups
Settings had grown to 21 rows in one list. It opens on five groups (This
device, Display, GNSS and radio, Network, System); Enter opens one, Back
returns to the groups, and Back from the groups leaves Settings.

SettingsMenu holds the groups and which one is open (host-tested: every
setting is in exactly one group). The guide, the how-tos, the README,
the scripts' messages and the firmware's own name the new paths, such as
"Settings > System > Firmware".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0162FokPdvY2KsS4NBfwyWPk
2026-10-10 00:11:52 +02:00

37 lines
2.2 KiB
Markdown

+++
title = "Set up the VPN"
description = "Put a WireGuard configuration on the device with your phone, import it, and check that the tunnel is up."
weight = 10
[extra]
tag = "VPN"
+++
You need a WireGuard server, and a **client configuration** made on it for the Cardputer, as you would make one for a phone: a `.conf` file.
1. Get the `.conf` onto the phone (or a computer on the same Wi-Fi), and name it **`wg0.conf`**.
2. On the Cardputer, open **Storage** and press <kbd>w</kbd>; open the page on the phone ([Move files with your phone](/howto/phone-files/)).
3. In the page, tap **New folder**, name it `vpn`, go into it, and **upload `wg0.conf`**.
4. On the Cardputer, press Back to stop sharing.
5. Open **Settings → Network → VPN → Import /vpn/wg0.conf**. You should see "Imported", and a question: **delete the file**. Say yes: the configuration is now in the device, and the file still holds the private key in clear.
6. Switch **VPN** to On. `VPN` appears in the Status Bar, and turns bright once the server has answered, usually within seconds. The page says "It is up".
7. To have it start by itself, switch on **Start with Wi-Fi**.
## Check it
On the device, in the [Shell](/guide/shell/): `vpn status`, then `ifconfig` (a `vpn` line, up) and `ping` the server's tunnel address. Or from another machine on the VPN, ping the Cardputer's tunnel address (the `Address` line of the file). More in [When the network doesn't work](/howto/network-check/).
## If it stays dim
| The page says | Try |
|---|---|
| waiting for Wi-Fi | Connect to a network first |
| waiting for the clock | Give it a moment after Wi-Fi connects: the time comes from the network |
| looking up the server | The server's name doesn't resolve from this network |
| no answer yet | The server's address or port, a firewall on the way, or the keys: check the server's side has this client's public key |
## What goes through it
Everything, if the file says `AllowedIPs = 0.0.0.0/0`; otherwise only the VPN's own subnet. To reach your home network behind the server, you need the first. See [VPN](/guide/vpn/#what-goes-through-it).
**The upload in step 3 is not encrypted,** and the file holds a private key: do it on a network you trust, with a key made for this device.