Skip to content
advanced

Advanced NordLayer WireGuard Deployment for Teams: Dedicated Gateways and Split Tunneling

Learn how to deploy NordLayer WireGuard with dedicated gateways, configure split tunneling, and manage team access securely. This advanced guide covers Windows and macOS clients, automation, and troubleshooting.

Windows macOS WireGuard Privacy/Anonymity

Overview

NordLayer WireGuard provides business-grade VPN tunnels with dedicated gateways, designed for teams that need secure and consistent network access. This advanced tutorial walks you through deploying NordLayer WireGuard with dedicated gateways, configuring split tunneling to optimize performance, and managing team access. It focuses on Windows and macOS clients but the principles apply to other platforms.

By the end, you will have a working setup that routes only necessary traffic through the VPN, maintains a stable IP for whitelisting, and allows granular control over team member access.

Prerequisites

  • A NordLayer business account with admin privileges.
  • At least one dedicated gateway provisioned in your NordLayer dashboard.
  • WireGuard client installed on each device (Windows, macOS).
  • Basic familiarity with command-line tools and network concepts.

Understanding Dedicated Gateways and Split Tunneling

Dedicated gateways provide a static IP address exclusively for your team, which is ideal for whitelisting in third-party services. NordLayer assigns a unique gateway to your organization, ensuring consistent egress IPs.

Split tunneling allows you to route only specific traffic through the VPN while sending the rest directly over the internet. This reduces latency for local resources and conserves VPN bandwidth. In WireGuard, split tunneling is controlled via the AllowedIPs setting in the peer configuration.

Steps

  1. Log in to the NordLayer admin panel
    Navigate to the Gateways section and locate your dedicated gateway. Note the gateway endpoint (e.g., gateway-123.nordlayer.com) and the public key.

  2. Generate a WireGuard configuration file
    In the admin panel, create a new WireGuard configuration for a user or device. Download the .conf file. It will look similar to this:

    [Interface]
    PrivateKey = <client-private-key>
    Address = 10.0.0.2/32
    DNS = 1.1.1.1
    
    [Peer]
    PublicKey = <gateway-public-key>
    Endpoint = gateway-123.nordlayer.com:51820
    AllowedIPs = 0.0.0.0/0, ::/0
    PersistentKeepalive = 25
    
  3. Install the WireGuard client on Windows
    Download and install the official WireGuard client from wireguard.com/install. After installation, open the app and click Add Tunnel > Import tunnel(s) from file. Select the downloaded .conf file.

  4. Install the WireGuard client on macOS
    Install WireGuard from the Mac App Store or from wireguard.com/install. Open the app, click Import tunnel(s) from file, and select your .conf file.

  5. Configure split tunneling
    Edit the tunnel in the WireGuard client. Modify the AllowedIPs line to include only the subnets you want to route through the VPN. For example, to route only traffic destined for 10.0.0.0/8 and 192.168.1.0/24, set:

    AllowedIPs = 10.0.0.0/8, 192.168.1.0/24
    

    Save the changes and activate the tunnel.

  6. Test the connection
    On Windows, open PowerShell and run:

    wg show
    

    On macOS, open Terminal and run:

    wg show
    

    You should see the latest handshake and data transfer. To verify your public IP, visit a service like ipinfo.io in your browser; it should show the dedicated gateway IP.

  7. Manage team access (optional)
    In the NordLayer admin panel, invite team members and assign them to the dedicated gateway. You can create separate configurations for each user to maintain individual accountability. Use the panel to revoke access when needed.

Troubleshooting

  • Handshake fails or no internet: Ensure UDP port 51820 is open outbound on your firewall. Check that the endpoint address resolves correctly.
  • DNS resolution issues: Verify the DNS setting in the [Interface] section. If you use split tunneling, ensure DNS servers are reachable via the routed subnets.
  • Split tunneling not working: Double-check the AllowedIPs syntax. Use CIDR notation and separate multiple subnets with commas. Remember that 0.0.0.0/0 routes all IPv4 traffic.
  • Cannot access local network: Add your local subnet (e.g., 192.168.0.0/16) to AllowedIPs if you need simultaneous access to LAN resources.
  • Slow performance: Limit AllowedIPs to only necessary subnets to reduce overhead. Also, ensure the dedicated gateway is in a region close to your team.

Summary

You have successfully deployed NordLayer WireGuard with dedicated gateways and split tunneling for your team. This setup provides a stable, secure connection with optimized traffic routing. Remember to regularly review access permissions and monitor gateway performance in the NordLayer dashboard. For more advanced scenarios, consult NordLayer's official documentation or contact their support team.