WireGuard (wg0.conf) Config, Keypair & Split-Tunnel CIDR Calculator (2026)

Generate complete WireGuard server and peer configurations (wg0.conf), synthesize clamped Curve25519 keypairs and 256-bit Pre-Shared Keys (PSK) locally in your browser, calculate exact AllowedIPs split-tunnel CIDR exclusions (excluding RFC 1918 LAN), and optimize MTU overhead.

WireGuard (wg0.conf) Config, Keypair & Split-Tunnel CIDR Calculator — Interactive Console
Runs locally in your browser • Instant output
WireGuard Split-Tunnel Routing Mode
Server (/etc/wireguard/wg0.conf)
# /etc/wireguard/wg0.conf (WireGuard Server)
[Interface]
Address = 10.66.66.1/24
ListenPort = 51820
PrivateKey = cO9nJ7vK2pL4mN6qR8sT0uV2wX4yZ6aB8cD0eF2gH4I=
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE

[Peer]
# Client Peer #1
PublicKey = wX2yZ4aB6cD8eF0gH2iJ4kL6mN8oP0qR2sT4uV6wX8Y=
PresharedKey = zA6bC8dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2B=
AllowedIPs = 10.66.66.2/32
Client Peer (peer-client.conf)
# peer-client.conf (WireGuard Client — EXCLUDE-LAN)
[Interface]
Address = 10.66.66.2/32
PrivateKey = mP4qR6sT8uV0wX2yZ4aB6cD8eF0gH2iJ4kL6mN8oP0Q=
DNS = 1.1.1.1, 1.0.0.1
MTU = 1420

[Peer]
PublicKey = kL3mN5pQ7rS9tU1vW3xY5zA7bC9dE1fG3hI5jK7lM9N=
PresharedKey = zA6bC8dE0fG2hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2B=
Endpoint = vpn.zerosuniverse.com:51820
AllowedIPs = 0.0.0.0/1, 128.0.0.0/2, 192.0.0.0/9, 192.128.0.0/11, 192.160.0.0/13, 192.169.0.0/16, 192.170.0.0/15, 192.172.0.0/14, 192.176.0.0/12, 192.192.0.0/10, 193.0.0.0/8, 194.0.0.0/7, 196.0.0.0/6, 200.0.0.0/5, 208.0.0.0/4, 224.0.0.0/3
PersistentKeepalive = 25
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![WireGuard (wg0.conf) Config, Keypair & Split-Tunnel CIDR Calculator](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/wireguard-vpn-config-split-tunnel-builder/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/wireguard-vpn-config-split-tunnel-builder/">WireGuard (wg0.conf) Config, Keypair & Split-Tunnel CIDR Calculator — ZerosUniverse</a>

2026 WireGuard Split-Tunnel AllowedIPs, MTU & PostUp Routing Table

2026 Verified Reference
Quick Answer & 2026 Technical Summary (wireguard config generator split tunnel calculator)Updated 2026 Standard

In WireGuard (`wg0.conf`), the client `[Peer] AllowedIPs` directive acts as both a routing table selector and an ingress source-IP filter: set `AllowedIPs = 0.0.0.0/0, ::/0` for a full-tunnel VPN, or specify internal CIDRs (`10.8.0.0/24, 192.168.1.0/24`) for split tunneling where internet traffic bypasses the VPN.

WireGuard Overhead = 60B (IPv4) or 80B (IPv6) → Optimal Ethernet MTU = 1420 (PPPoE/LTE MTU = 1380)
Full Tunnel Routing: AllowedIPs = 0.0.0.0/0, ::/0
Optimal WireGuard MTU: 1420 bytes (1500 Ethernet - 80B IPv6 WG header)
NAT Traversal Keepalive: PersistentKeepalive = 25 (Seconds)
WireGuard Routing ScenarioConfig Directive / CIDR ValueTraffic Flow BehaviorOperational & Security Best Practice
Full Tunnel VPN (All Traffic)AllowedIPs = 0.0.0.0/0, ::/0Routes 100% of IPv4 & IPv6 packets via WG serverPair with DNS = 1.1.1.1 to prevent ISP DNS leaks
Corporate / Homelab Split TunnelAllowedIPs = 10.66.66.0/24, 192.168.10.0/24Only private subnet traffic enters encrypted tunnelDirect internet speed remains untouched (zero VPN lag)
Full Tunnel Excluding Local LANAllowedIPs = 0.0.0.0/1, 128.0.0.0/1 (plus LAN bypass)Routes internet via VPN while keeping local printers/NASAvoids 0.0.0.0/0 kill-switch overriding local subnet
MTU Fragmentation & MSS FixMTU = 1420 (or MTU = 1380 on 5G/PPPoE)Prevents PMTUD blackholes on TLS handshakesUse 1380 if websites hang or video streams stall
Server NAT Masquerade (PostUp)PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADEEnables IPv4 packet forwarding out server NICRequires net.ipv4.ip_forward=1 in /etc/sysctl.conf
Post-Quantum PSK & CGNAT KeepalivePresharedKey = <wg genpsk> | PersistentKeepalive = 25Adds 256-bit symmetric layer + keeps NAT port openDefends Curve25519 against harvest-now-decrypt-later
In-Depth ZerosUniverse Tutorial

What is a VPN (Virtual Private Network) & How WireGuard Works

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use WireGuard (wg0.conf) Config, Keypair & Split-Tunnel CIDR Calculator

01

Generate Fresh Clamped Keys & Pre-Shared Key Locally

Click Rotate Cryptographic Keys to generate new Base64-encoded Server and Peer keys alongside a 256-bit PresharedKey via Web Crypto CSPRNG.

02

Select Your Routing Mode (Full Tunnel vs. LAN-Bypass Split Tunnel)

Pick Full Tunnel (0.0.0.0/0), Public Internet Only (Excluding RFC 1918 Local LANs), or Private VPN Subnet Only (10.66.66.0/24).

03

Configure Endpoint, Tunnel IPs, DNS & Link MTU Profile

Enter your server's public IP/hostname and UDP port (default 51820), choose your physical link medium (Standard Ethernet 1500, PPPoE 1492, or Cellular 1428), and toggle NAT keepalives.

04

Copy Matched Server & Client wg0.conf Configs

Copy or download both configuration files and run 'wg-quick up wg0' on your server and client.

Key Capabilities & Technical Architecture

Zero-Upload Curve25519 Keypair & PresharedKey Synthesizer

Generate RFC 7748 clamped 32-byte Curve25519 private keys (bits 0,1,2 cleared; bit 254 set; bit 255 cleared) and 256-bit post-quantum Pre-Shared Keys using browser CSPRNG.

AllowedIPs Split-Tunnel CIDR Exclusion Calculator

Switch seamlessly between Full-Tunnel (0.0.0.0/0, ::/0), LAN-Bypass Split Tunnel (all internet IPv4 blocks EXCEPT RFC 1918 10/8, 172.16/12, 192.168/16), and Intranet-Only routing.

Synchronized Server & Peer wg0.conf Generator

Output matched Server [Interface]/[Peer] and Client [Interface]/[Peer] configuration files complete with iptables/nftables MASQUERADE PostUp/PostDown hooks and PersistentKeepalive.

WireGuard Packet Encapsulation & MTU Overhead Calculator

Compute optimal tunnel MTU across IPv4/IPv6 Ethernet (1500), PPPoE Fiber (1492), and LTE/5G CGNAT (1428) links to eliminate TCP MSS clamping fragmentation and packet drops.

Practical Use Cases

Bypassing Local LAN Printers & NAS While Routing Internet Over VPN

Generate the exact 19-subnet AllowedIPs CIDR list that tunnels all public IPv4 traffic through WireGuard while leaving 192.168.0.0/16, 172.16.0.0/12, and 10.0.0.0/8 on local Wi-Fi.

Self-Hosted Home Lab & Cloud VPS WireGuard Deployment

Spin up a hardened Ubuntu/Debian WireGuard gateway with PostUp NAT forwarding, DNS leak protection, and post-quantum PresharedKey defense in 60 seconds.

Fixing Stalled HTTPS / SSH Connections Over PPPoE or Cellular VPNs

Calculate the exact 60-byte (IPv4) or 80-byte (IPv6) WireGuard header overhead to set an optimal 1420, 1412, or 1360 MTU.

Frequently Asked Questions (FAQs)

Why doesn't WireGuard have an 'ExcludeIPs' setting for local LAN split-tunneling?+

WireGuard's Cryptokey Routing design intentionally binds every peer's public key directly to a positive list of permitted source/destination CIDR blocks (AllowedIPs). To route all internet traffic through the VPN while excluding RFC 1918 local networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), you replace 0.0.0.0/0 with the complement set of 19 CIDR blocks that mathematically cover the rest of the IPv4 space.

Why is WireGuard's default MTU 1420 instead of 1500?+

A standard Ethernet frame has a 1500-byte Maximum Transmission Unit (MTU). WireGuard encapsulates inner packets inside UDP: adding a 20-byte IPv4 header (or 40-byte IPv6 header), an 8-byte UDP header, a 4-byte WireGuard type/reserved field, a 4-byte key index, an 8-byte ChaCha20 nonce counter, and a 16-byte Poly1305 authentication tag. Over IPv6, 40 + 8 + 32 = 80 bytes of overhead, leaving 1500 − 80 = 1420 bytes for the inner payload.

What does the PresharedKey (PSK) option in WireGuard protect against?+

WireGuard uses Curve25519 ECDH for key exchange, which is secure against classical computers but theoretically vulnerable to a future fault-tolerant quantum computer running Shor's algorithm ('harvest now, decrypt later'). Adding a symmetric 256-bit PresharedKey mixes an additional HKDF key input into the Noise_IKpsk2 handshake, achieving post-quantum resistance under Grover's algorithm.

When do I need 'PersistentKeepalive = 25' in a WireGuard config?+

WireGuard is cryptographically silent—if no data is being sent, it transmits zero packets. If a client sits behind a Stateful NAT router or carrier-grade NAT (CGNAT) and wants the server to be able to initiate connections back to the client, sending an authenticated empty keepalive packet every 25 seconds prevents the NAT translation table entry from expiring.

What is Curve25519 key clamping?+

Per RFC 7748, any random 32-byte array becomes a valid X25519 private scalar by clearing the lowest 3 bits of byte 0 (byte[0] &= 248, ensuring the scalar is a multiple of the cofactor 8 to prevent small-subgroup attacks), clearing the highest bit of byte 31 (byte[31] &= 127), and setting the second-highest bit of byte 31 (byte[31] |= 64, ensuring constant-time Montgomery ladder execution).