Skip to content
intermediate

Configure ChangeMyIP WireGuard on Linux

Set up a ChangeMyIP WireGuard tunnel on Linux using wg-quick, with full-tunnel or split-tunnel routing options.

Linux WireGuard Privacy/Anonymity

Overview

This tutorial shows how to configure a ChangeMyIP WireGuard tunnel on Linux. ChangeMyIP lists WireGuard as a supported protocol alongside HTTP, SOCKS5, Shadowsocks, Trojan, and DNS. WireGuard creates an encrypted network interface rather than a local proxy. Use the WireGuard configuration details provided by ChangeMyIP for your account.

Steps

  1. Log in to ChangeMyIP and locate or generate the WireGuard configuration for your chosen endpoint. If your plan does not include WireGuard, use an HTTP or SOCKS5 proxy tutorial instead.
  2. Install WireGuard tools on your Linux distribution. For Debian or Ubuntu: sudo apt update && sudo apt install wireguard
  3. Save the ChangeMyIP WireGuard configuration as /etc/wireguard/changeip.conf.
  4. Restrict permissions: sudo chmod 600 /etc/wireguard/changeip.conf
  5. Bring the tunnel up: sudo wg-quick up changeip
  6. Check the interface: sudo wg show
  7. Test your public IP: curl https://ifconfig.me
  8. If the IP matches the ChangeMyIP endpoint, the tunnel is active.
  9. For split tunneling, edit the configuration's AllowedIPs so only the target subnets use the tunnel. Keep DNS set only if you want DNS through the tunnel.
  10. To stop the tunnel: sudo wg-quick down changeip
  11. To start it at boot: sudo systemctl enable wg-quick@changeip
  12. If the tunnel fails, check the endpoint, keys, and firewall rules, and confirm that your ChangeMyIP plan includes WireGuard.