VPN Gateway
VPN Gateway connects your laptop or phone to the private networks of your router over WireGuard. Servers are reachable by their private addresses, without public IPs or open SSH ports. The gateway runs on your router and uses its public address.
Turn it on
New accounts get the gateway with the default router. On an older account open VPN Gateway in the panel and press Enable. The first start takes about a minute.
The gateway needs a router. Without one the page says so and links to Routers.
Add a device
- Open VPN Gateway and press Add device.
- Give it a name, for example
laptop, and choose the mode (see below). - Save the config. Scan the QR code with the WireGuard app on a phone, or download the
.conffile for a computer.
The config holds the private key of the device and is shown only once. We do not keep the key. If the config is lost, remove the device and add it again.
Install WireGuard and import the config
Get the official app for your system from wireguard.com/install. On a phone it is WireGuard in the App Store or Google Play. Any other WireGuard client works too.
| System | How to import |
|---|---|
| Windows, macOS | Open WireGuard, press Import tunnel(s) from file, choose the .conf you downloaded, then Activate. |
| iPhone, iPad | Open WireGuard, press +, then Create from QR code and scan the code from the panel. Turn the tunnel on. |
| Android | Open WireGuard, press +, then Scan from QR code and scan the code from the panel. Turn the tunnel on. |
| Linux | Install wireguard-tools, copy the file to /etc/wireguard/scamp.conf and run sudo wg-quick up scamp. |
On Linux the DNS line of the config needs resolvconf. On Debian and Ubuntu install it with the tools:
sudo apt install wireguard-tools resolvconf
sudo cp ~/Downloads/scamp-wg-1a2b3c.conf /etc/wireguard/scamp.conf
sudo wg-quick up scamp
# start it on every boot
sudo systemctl enable wg-quick@scamp
To check the tunnel, connect to a server by its private address, for example ssh [email protected].
Split and full tunnel
| Mode | What goes through the VPN | Price |
|---|---|---|
| Private networks (split tunnel) | Only your private networks. Everything else goes through the device's own internet. | €0.50 a month |
| All traffic (full tunnel) | Everything. The device goes to the internet from the public address of your router. | €2 a month |
Full tunnel gives all your devices one static outgoing address. That is useful for allowlists at banks, CRMs or other people's servers.
The mode is enforced on the gateway. A split tunnel device reaches your private networks and nothing else, even if its config is edited by hand.
What is in the config
| Field | Value |
|---|---|
Address | The device address in the VPN subnet 100.64.0.0/24 |
DNS | 100.64.0.1, the gateway. It answers for your Private DNS zones and forwards the rest. |
MTU | 1280, so the tunnel also works behind PPPoE and other short links |
Endpoint | Public address of your router, UDP port 51820 |
AllowedIPs | Your private networks and the VPN subnet, or 0.0.0.0/0 for full tunnel |
Port 51820 on the router is reserved for the gateway and cannot be used in a port forward.
Status and traffic
The page shows which devices are connected now, when each was last seen, where it connects from and how much it sent and received. The graph covers the last hours or days.
When you remove a device, it loses access right away.
Prices and limits
A device is billed by the hour from the moment it is added, €0.50 a month for split tunnel and €2 a month for full tunnel. The first hour is charged when you add it. Charges appear in Billing under VPN devices.
Traffic of the VPN counts as traffic of your router. Outgoing traffic is in the 5 TB a month included in the account, see Billing.
An account can have 10 devices. Need more? Request an increase on the Limits page in the panel.
The gateway is part of the router. Private networks on another router get their own gateway.