How to set up WireGuard VPN on TP-Link wireless router
Archer BE9300( V1 ) , Archer AX55( V1 V2 ) , Archer AX53( V1 ) , Archer GXE75 , Archer BE700 Pro , Archer AX55 Pro( V1 ) , Archer BE230 , Archer BE550( V1 ) , Archer BE700 , Archer BE11000 Pro , Archer BE800( V1 ) , Archer BE900( V1 ) , Archer AX80( V1 ) , Archer GE800( V1 ) , Archer BE3600 , Archer BE805( V1 )
Recent updates may have expanded access to feature(s) discussed in this FAQ. Visit your product's support page, select the correct hardware version for your device and check either the Datasheet or the firmware section for the latest improvements added to your product.
User’s Application Scenario
When the user needs a secure, fast, and modern VPN protocol to remotely access the internal network. Based on the UDP protocol, WireGuard VPN uses modern encryption algorithms to improve work efficiency.
How to Set up Archer AX55 as a WireGuard VPN Server
WireGuard VPN Server is used to create a Wire Guard VPN connection for remote devices to access your home network.
Step 1. Set up WireGuard VPN Server on Your Router
1. Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router.
2. Go to Advanced > VPN Server > WireGuard, and tick the Enable box of WireGuard.
3. View the default WireGuard VPN settings, as shown above. The parameters are automatically filled in, and do NOT change them unless necessary.
4. Select your Client Access type. Select Home Network Only if you only want the remote device to access your home network; select Internet and Home Network if you also want the remote device to access the internet through the VPN Server.
5. (Optional) Click Advanced Settings to display more settings. If DNS is turned on, the router will become the DNS server of the VPN client that establishes a connection with it. Change the Persistent Keepalive time (25 seconds by default) to send out heartbeat regularly, you can also click RENEW KEY to update the private key and public key.
Step 2. Create accounts that can be used by remote clients to connect to the VPN server.
1. Locate the Account List section. Click Add to create an account.
2. Specify a name for this account.
3. Enter the address of the virtual interface assigned to this account. Do NOT change it unless necessary.
4. Traffic sent from the WireGuard VPN client to the allowed IPs (client) will be transmitted through the tunnel. By default, all network traffic from clients will be transmitted through the tunnel. Do NOT change it unless necessary.
5. Traffic sent from the WireGuard VPN server to the allowed IPs (server) will be transmitted through the tunnel. Do NOT change it unless necessary.
6. Enable or disable the Pre-shared key.
7. Click SAVE.
Note: One account can only be used by one WireGuard VPN client at the same time to connect to the WireGuard VPN server.
8. Connect to the WireGuard server:
On the Account List, click in the Modify column of the corresponding account.
• For mobile phones, download WireGuard App from Google Play or Apple Store, then use the App to scan the QR Code to connect to this server.
• For other devices (e.g. TP-Link WireGuard VPN client), click EXPORT to save the WireGuard VPN configuration file which will be used by the remote device to access your router.
9. On the account list, you can click the button to modify the VPN server settings, connect to the server, or delete the account.
How to Configure WireGuard VPN Client on Archer AX55
Please follow the steps below to set up and configure the WireGuard VPN Client on the Archer AX55:
1. Download the configuration file from your VPN provider.
2. We currently support some basic parameters of the WireGuard configuration file as Pic 1. If the configuration file you are using includes IPv6 address, MTU or many more (example as Pic 2), please edit the file and delete those parameters, then save the file.
3. Visit http://tplinkwifi.net, and log in with your TP-Link ID or the password you set for the router. Go to Advanced > VPN Client.
4. Enable VPN Client, and click SAVE.
5. Click Add button in the up-right of the Server List, specify a description for the VPN, and choose WireGuard as the VPN Type, click BROWSE to import the configuration file provided by your VPN provider, then click SAVE.
6. Check and enable the WireGuard in the Server List, add and enable the VPN Access for the devices that will use the VPN function.
Note: It's NOT suggested to use the same configuration file on multiple VPN Clients simultaneously. You could import the configuration file into your mobile phones as well as the router, but you are not allowed to connect to the VPN server simultaneously based on WireGuard protocols.
Is this faq useful?
Your feedback helps improve this site.
What’s your concern with this article?
- Dissatisfied with product
- Too Complicated
- Confusing Title
- Does not apply to me
- Too Vague
- Other
We'd love to get your feedback, please let us know how we can improve this content.
Thank you
We appreciate your feedback.
Click here to contact TP-Link technical support.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.
This website uses cookies to improve website navigation, analyze online activities and have the best possible user experience on our website. You can object to the use of cookies at any time. You can find more information in our privacy policy . Don’t show again
This website uses cookies to improve website navigation, analyze online activities and have the best possible user experience on our website. You can object to the use of cookies at any time. You can find more information in our privacy policy . Don’t show again
Basic Cookies
These cookies are necessary for the website to function and cannot be deactivated in your systems.
TP-Link
accepted_local_switcher, tp_privacy_base, tp_privacy_marketing, tp_smb-select-product_scence, tp_smb-select-product_scenceSimple, tp_smb-select-product_userChoice, tp_smb-select-product_userChoiceSimple, tp_smb-select-product_userInfo, tp_smb-select-product_userInfoSimple, tp_top-banner, tp_popup-bottom, tp_popup-center, tp_popup-right-middle, tp_popup-right-bottom, tp_productCategoryType
Livechat
__livechat, __lc2_cid, __lc2_cst, __lc_cid, __lc_cst, CASID
Youtube
id, VISITOR_INFO1_LIVE, LOGIN_INFO, SIDCC, SAPISID, APISID, SSID, SID, YSC, __Secure-1PSID, __Secure-1PAPISID, __Secure-1PSIDCC, __Secure-3PSID, __Secure-3PAPISID, __Secure-3PSIDCC, 1P_JAR, AEC, NID, OTZ
Analysis and Marketing Cookies
Analysis cookies enable us to analyze your activities on our website in order to improve and adapt the functionality of our website.
The marketing cookies can be set through our website by our advertising partners in order to create a profile of your interests and to show you relevant advertisements on other websites.
Google Analytics & Google Tag Manager
_gid, _ga_<container-id>, _ga, _gat_gtag_<container-id>
Google Ads & DoubleClick
test_cookie, _gcl_au
Meta Pixel
_fbp
Crazy Egg
cebsp_, _ce.s, _ce.clock_data, _ce.clock_event, cebs
lidc, AnalyticsSyncHistory, UserMatchHistory, bcookie, li_sugr, ln_or