Advanced NordLayer WireGuard Deployment for Teams: Dedicated Gateways and Split Tunneling
Learn how to deploy NordLayer WireGuard with dedicated gateways, configure split tunneling, and manage team access securely. This advanced guide covers Windows and macOS clients, automation, and troubleshooting.
Overview
NordLayer WireGuard provides business-grade VPN tunnels with dedicated gateways, designed for teams that need secure and consistent network access. This advanced tutorial walks you through deploying NordLayer WireGuard with dedicated gateways, configuring split tunneling to optimize performance, and managing team access. It focuses on Windows and macOS clients but the principles apply to other platforms.
By the end, you will have a working setup that routes only necessary traffic through the VPN, maintains a stable IP for whitelisting, and allows granular control over team member access.
Prerequisites
- A NordLayer business account with admin privileges.
- At least one dedicated gateway provisioned in your NordLayer dashboard.
- WireGuard client installed on each device (Windows, macOS).
- Basic familiarity with command-line tools and network concepts.
Understanding Dedicated Gateways and Split Tunneling
Dedicated gateways provide a static IP address exclusively for your team, which is ideal for whitelisting in third-party services. NordLayer assigns a unique gateway to your organization, ensuring consistent egress IPs.
Split tunneling allows you to route only specific traffic through the VPN while sending the rest directly over the internet. This reduces latency for local resources and conserves VPN bandwidth. In WireGuard, split tunneling is controlled via the AllowedIPs setting in the peer configuration.
Steps
-
Log in to the NordLayer admin panel
Navigate to the Gateways section and locate your dedicated gateway. Note the gateway endpoint (e.g.,gateway-123.nordlayer.com) and the public key. -
Generate a WireGuard configuration file
In the admin panel, create a new WireGuard configuration for a user or device. Download the.conffile. It will look similar to this:[Interface] PrivateKey = <client-private-key> Address = 10.0.0.2/32 DNS = 1.1.1.1 [Peer] PublicKey = <gateway-public-key> Endpoint = gateway-123.nordlayer.com:51820 AllowedIPs = 0.0.0.0/0, ::/0 PersistentKeepalive = 25 -
Install the WireGuard client on Windows
Download and install the official WireGuard client from wireguard.com/install. After installation, open the app and click Add Tunnel > Import tunnel(s) from file. Select the downloaded.conffile. -
Install the WireGuard client on macOS
Install WireGuard from the Mac App Store or from wireguard.com/install. Open the app, click Import tunnel(s) from file, and select your.conffile. -
Configure split tunneling
Edit the tunnel in the WireGuard client. Modify theAllowedIPsline to include only the subnets you want to route through the VPN. For example, to route only traffic destined for10.0.0.0/8and192.168.1.0/24, set:AllowedIPs = 10.0.0.0/8, 192.168.1.0/24Save the changes and activate the tunnel.
-
Test the connection
On Windows, open PowerShell and run:wg showOn macOS, open Terminal and run:
wg showYou should see the latest handshake and data transfer. To verify your public IP, visit a service like ipinfo.io in your browser; it should show the dedicated gateway IP.
-
Manage team access (optional)
In the NordLayer admin panel, invite team members and assign them to the dedicated gateway. You can create separate configurations for each user to maintain individual accountability. Use the panel to revoke access when needed.
Troubleshooting
- Handshake fails or no internet: Ensure UDP port
51820is open outbound on your firewall. Check that the endpoint address resolves correctly. - DNS resolution issues: Verify the
DNSsetting in the[Interface]section. If you use split tunneling, ensure DNS servers are reachable via the routed subnets. - Split tunneling not working: Double-check the
AllowedIPssyntax. Use CIDR notation and separate multiple subnets with commas. Remember that0.0.0.0/0routes all IPv4 traffic. - Cannot access local network: Add your local subnet (e.g.,
192.168.0.0/16) toAllowedIPsif you need simultaneous access to LAN resources. - Slow performance: Limit
AllowedIPsto only necessary subnets to reduce overhead. Also, ensure the dedicated gateway is in a region close to your team.
Summary
You have successfully deployed NordLayer WireGuard with dedicated gateways and split tunneling for your team. This setup provides a stable, secure connection with optimized traffic routing. Remember to regularly review access permissions and monitor gateway performance in the NordLayer dashboard. For more advanced scenarios, consult NordLayer's official documentation or contact their support team.