How to Configure NordLayer WireGuard on iPhone and Android
A practical walkthrough for importing a NordLayer WireGuard tunnel onto iOS and Android devices, verifying the handshake and exit address, and fixing the mobile-specific problems that break WireGuard connections.
Overview
NordLayer WireGuard delivers business-grade WireGuard tunnels over dedicated gateways with flat monthly billing, which suits teams that need a handful of staff connecting from phones and tablets rather than from managed laptops. Because WireGuard is a standard protocol, the mobile workflow is the same whether your tunnels come from NordLayer or another WireGuard-capable provider: you import a peer configuration, bring the tunnel up, and confirm that traffic actually leaves through the gateway.
This tutorial covers the official WireGuard clients on iOS and Android, the import methods each platform supports, and the verification and troubleshooting steps that catch the most common mobile failures.
Prerequisites
- An active NordLayer seat or account issued by your organisation's administrator, with a WireGuard peer created for this specific device.
- The tunnel details: an interface private key, a tunnel address, a DNS resolver, the gateway public key, and the gateway endpoint (host and UDP port).
- Either a QR code or a
.conffile supplied by whoever manages the gateway. - The official WireGuard client installed from the App Store or Google Play.
- Permission to add a VPN configuration to the device. On MDM-managed phones this may be blocked until your administrator approves it.
What each field does
| Field | Example | Purpose |
|---|---|---|
PrivateKey |
base64 string | Identifies this device to the gateway. Never share it. |
Address |
10.8.0.14/32 |
The tunnel IP assigned to this device. |
DNS |
10.8.0.1 |
Resolver reachable through the tunnel. |
PublicKey |
base64 string | The gateway's key, used to encrypt traffic to it. |
Endpoint |
gateway.example.com:51820 |
Where the device sends handshake packets. |
AllowedIPs |
0.0.0.0/0, ::/0 or 10.8.0.0/24 |
Which traffic is routed into the tunnel. |
A tunnel template in .conf form looks like this:
[Interface]
PrivateKey = <this-device-private-key>
Address = 10.8.0.14/32
DNS = 10.8.0.1
[Peer]
PublicKey = <gateway-public-key>
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = <gateway-host>:51820
PersistentKeepalive = 25
Set AllowedIPs to 0.0.0.0/0, ::/0 to route all traffic through the gateway, or to the internal subnet only if your administrator wants a split tunnel. PersistentKeepalive of 25 is a common choice on mobile networks because carrier NAT otherwise drops idle sessions.
Steps
- Confirm the tunnel is meant for this device. Each phone should have its own peer key pair. Importing the same configuration on two devices causes handshakes to flap and disconnects on both.
- Install the official WireGuard client. On iOS, search the App Store for WireGuard and install the app published by WireGuard Development Team. On Android, install the equivalent app from Google Play. Avoid third-party VPN clients that merely bundle WireGuard.
- Import on iOS. Open the app, tap the plus button, then choose Create from QR code and scan the code your administrator supplied, or choose Create from file or archive and select the
.conffile from Files. Give the tunnel a recognisable name such asNordLayer-Gateway-EU, tap Save, and accept the system prompt to add a VPN configuration. - Import on Android. Open the app, tap the plus button, then choose Scan from QR code or Import from file or archive. Select the
.conffile in the file picker, allow the app to add a VPN profile, and confirm the tunnel name. - Review the imported settings before connecting. Open the tunnel entry and check that
Endpoint,AllowedIPs, andDNSmatch what your administrator provided. A truncated QR code or a stale file is the most common cause of a tunnel that never completes a handshake. - Connect the tunnel. Toggle the switch next to the tunnel. The status should move to Active within a couple of seconds, and the OS will show a VPN indicator in the status bar.
- Verify the handshake and the exit address. Use the checks in the next section. Do not assume the tunnel is working just because the toggle is on.
- Set up on-demand behaviour, if it is appropriate. On iOS, open the tunnel, tap Edit, and enable On-Demand with a rule that suits the device. On Android, use the system setting under Settings → Network & internet → VPN → WireGuard to enable Always-on VPN and optionally Block connections without VPN. Availability of these options varies by OS version and by MDM policy.
- Test the tunnel on both Wi-Fi and cellular. Mobile networks frequently block or throttle UDP, so a tunnel that works on office Wi-Fi may fail on a carrier network.
- Store and rotate the configuration. Keep an offline copy of the
.confin a password manager or encrypted vault, and delete old peers from the gateway once a device is retired. Rotate keys if a phone is lost.
Verifying the tunnel
The WireGuard app is the most reliable diagnostic on mobile. Open the active tunnel and check the Latest handshake and transfer counters:
- Latest handshake should show a value within the last two minutes while the tunnel is idle with keepalive enabled.
- Transfer should show both received and sent bytes increasing as you browse.
- A handshake that stays at Never means the device cannot reach the endpoint, not that the tunnel is connected but idle.
To confirm which address the internet sees, visit an IP echo page in the phone's browser and compare the result with the address your administrator expects for that dedicated gateway. If you have a laptop on the same gateway, you can confirm the expected value first:
# Run from a device already using the same gateway.
# Whatever this prints is the address a phone on the same gateway should also report.
curl -s https://ifconfig.me
Expected output is a single IP address with no trailing text:
203.0.113.42
Because NordLayer uses dedicated gateways rather than a shared pool, that address should stay stable between sessions, which is helpful when internal services or partners allowlist a specific IP.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Status shows connected, handshake stays at Never | UDP blocked by the mobile carrier or a captive portal | Switch to another network, disconnect from the captive portal, or ask your administrator for a gateway on a different port |
| Handshake completes, no sites load | DNS unreachable through the tunnel, or AllowedIPs misconfigured |
Confirm the resolver is topologically inside the tunnel; re-import a fresh configuration |
| Internal tools work, public sites do not | Split tunnel with AllowedIPs limited to the internal subnet |
Expected behaviour; add 0.0.0.0/0, ::/0 only if full-tunnel routing is intended |
| Works on Wi-Fi, fails on cellular | Carrier NAT or UDP filtering | Enable PersistentKeepalive = 25, retry, and test from a different carrier if needed |
| Tunnel drops after a few minutes idle | No keepalive, or aggressive OS battery management | Set keepalive, and exempt the WireGuard app from battery optimisation on Android |
| Two devices disconnect each other | Same peer key imported on both | Request a separate peer per device from your administrator |
| Import fails or app reports an invalid key | Truncated QR code or corrupted .conf file |
Re-request the configuration and import from the file rather than the QR code |
| Battery drains noticeably | On-demand rule keeps the tunnel up on every network | Narrow the on-demand rule to untrusted networks, or use a split tunnel if policy allows |
Summary
- WireGuard on iOS and Android follows a standard import-then-verify flow; NordLayer supplies the tunnel details, and the official client does the rest.
- Always import a configuration meant for that single device, and never reuse one peer key across two phones.
- Treat the handshake counter, not the on/off toggle, as proof that the tunnel is working.
- Set
PersistentKeepalive = 25on mobile devices so carrier NAT does not silently kill idle sessions. - Test on cellular as well as Wi-Fi, and keep an offline copy of the configuration so a lost or wiped phone can be replaced quickly.