Skip to content
intermediate

How to Configure NordLayer WireGuard on iPhone and Android

A practical walkthrough for importing a NordLayer WireGuard tunnel onto iOS and Android devices, verifying the handshake and exit address, and fixing the mobile-specific problems that break WireGuard connections.

iOS Android WireGuard Privacy/Anonymity

Overview

NordLayer WireGuard delivers business-grade WireGuard tunnels over dedicated gateways with flat monthly billing, which suits teams that need a handful of staff connecting from phones and tablets rather than from managed laptops. Because WireGuard is a standard protocol, the mobile workflow is the same whether your tunnels come from NordLayer or another WireGuard-capable provider: you import a peer configuration, bring the tunnel up, and confirm that traffic actually leaves through the gateway.

This tutorial covers the official WireGuard clients on iOS and Android, the import methods each platform supports, and the verification and troubleshooting steps that catch the most common mobile failures.

Prerequisites

  • An active NordLayer seat or account issued by your organisation's administrator, with a WireGuard peer created for this specific device.
  • The tunnel details: an interface private key, a tunnel address, a DNS resolver, the gateway public key, and the gateway endpoint (host and UDP port).
  • Either a QR code or a .conf file supplied by whoever manages the gateway.
  • The official WireGuard client installed from the App Store or Google Play.
  • Permission to add a VPN configuration to the device. On MDM-managed phones this may be blocked until your administrator approves it.

What each field does

Field Example Purpose
PrivateKey base64 string Identifies this device to the gateway. Never share it.
Address 10.8.0.14/32 The tunnel IP assigned to this device.
DNS 10.8.0.1 Resolver reachable through the tunnel.
PublicKey base64 string The gateway's key, used to encrypt traffic to it.
Endpoint gateway.example.com:51820 Where the device sends handshake packets.
AllowedIPs 0.0.0.0/0, ::/0 or 10.8.0.0/24 Which traffic is routed into the tunnel.

A tunnel template in .conf form looks like this:

[Interface]
PrivateKey = <this-device-private-key>
Address = 10.8.0.14/32
DNS = 10.8.0.1

[Peer]
PublicKey = <gateway-public-key>
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = <gateway-host>:51820
PersistentKeepalive = 25

Set AllowedIPs to 0.0.0.0/0, ::/0 to route all traffic through the gateway, or to the internal subnet only if your administrator wants a split tunnel. PersistentKeepalive of 25 is a common choice on mobile networks because carrier NAT otherwise drops idle sessions.

Steps

  1. Confirm the tunnel is meant for this device. Each phone should have its own peer key pair. Importing the same configuration on two devices causes handshakes to flap and disconnects on both.
  2. Install the official WireGuard client. On iOS, search the App Store for WireGuard and install the app published by WireGuard Development Team. On Android, install the equivalent app from Google Play. Avoid third-party VPN clients that merely bundle WireGuard.
  3. Import on iOS. Open the app, tap the plus button, then choose Create from QR code and scan the code your administrator supplied, or choose Create from file or archive and select the .conf file from Files. Give the tunnel a recognisable name such as NordLayer-Gateway-EU, tap Save, and accept the system prompt to add a VPN configuration.
  4. Import on Android. Open the app, tap the plus button, then choose Scan from QR code or Import from file or archive. Select the .conf file in the file picker, allow the app to add a VPN profile, and confirm the tunnel name.
  5. Review the imported settings before connecting. Open the tunnel entry and check that Endpoint, AllowedIPs, and DNS match what your administrator provided. A truncated QR code or a stale file is the most common cause of a tunnel that never completes a handshake.
  6. Connect the tunnel. Toggle the switch next to the tunnel. The status should move to Active within a couple of seconds, and the OS will show a VPN indicator in the status bar.
  7. Verify the handshake and the exit address. Use the checks in the next section. Do not assume the tunnel is working just because the toggle is on.
  8. Set up on-demand behaviour, if it is appropriate. On iOS, open the tunnel, tap Edit, and enable On-Demand with a rule that suits the device. On Android, use the system setting under Settings → Network & internet → VPN → WireGuard to enable Always-on VPN and optionally Block connections without VPN. Availability of these options varies by OS version and by MDM policy.
  9. Test the tunnel on both Wi-Fi and cellular. Mobile networks frequently block or throttle UDP, so a tunnel that works on office Wi-Fi may fail on a carrier network.
  10. Store and rotate the configuration. Keep an offline copy of the .conf in a password manager or encrypted vault, and delete old peers from the gateway once a device is retired. Rotate keys if a phone is lost.

Verifying the tunnel

The WireGuard app is the most reliable diagnostic on mobile. Open the active tunnel and check the Latest handshake and transfer counters:

  • Latest handshake should show a value within the last two minutes while the tunnel is idle with keepalive enabled.
  • Transfer should show both received and sent bytes increasing as you browse.
  • A handshake that stays at Never means the device cannot reach the endpoint, not that the tunnel is connected but idle.

To confirm which address the internet sees, visit an IP echo page in the phone's browser and compare the result with the address your administrator expects for that dedicated gateway. If you have a laptop on the same gateway, you can confirm the expected value first:

# Run from a device already using the same gateway.
# Whatever this prints is the address a phone on the same gateway should also report.
curl -s https://ifconfig.me

Expected output is a single IP address with no trailing text:

203.0.113.42

Because NordLayer uses dedicated gateways rather than a shared pool, that address should stay stable between sessions, which is helpful when internal services or partners allowlist a specific IP.

Troubleshooting

Symptom Likely cause Fix
Status shows connected, handshake stays at Never UDP blocked by the mobile carrier or a captive portal Switch to another network, disconnect from the captive portal, or ask your administrator for a gateway on a different port
Handshake completes, no sites load DNS unreachable through the tunnel, or AllowedIPs misconfigured Confirm the resolver is topologically inside the tunnel; re-import a fresh configuration
Internal tools work, public sites do not Split tunnel with AllowedIPs limited to the internal subnet Expected behaviour; add 0.0.0.0/0, ::/0 only if full-tunnel routing is intended
Works on Wi-Fi, fails on cellular Carrier NAT or UDP filtering Enable PersistentKeepalive = 25, retry, and test from a different carrier if needed
Tunnel drops after a few minutes idle No keepalive, or aggressive OS battery management Set keepalive, and exempt the WireGuard app from battery optimisation on Android
Two devices disconnect each other Same peer key imported on both Request a separate peer per device from your administrator
Import fails or app reports an invalid key Truncated QR code or corrupted .conf file Re-request the configuration and import from the file rather than the QR code
Battery drains noticeably On-demand rule keeps the tunnel up on every network Narrow the on-demand rule to untrusted networks, or use a split tunnel if policy allows

Summary

  • WireGuard on iOS and Android follows a standard import-then-verify flow; NordLayer supplies the tunnel details, and the official client does the rest.
  • Always import a configuration meant for that single device, and never reuse one peer key across two phones.
  • Treat the handshake counter, not the on/off toggle, as proof that the tunnel is working.
  • Set PersistentKeepalive = 25 on mobile devices so carrier NAT does not silently kill idle sessions.
  • Test on cellular as well as Wi-Fi, and keep an offline copy of the configuration so a lost or wiped phone can be replaced quickly.