Skip to content
intermediate

How to Configure NordLayer WireGuard on macOS and Linux

Set up NordLayer WireGuard on macOS and Linux using WireGuard tools, import a dedicated gateway config, and verify secure team connectivity.

macOS Linux WireGuard

Overview

NordLayer WireGuard is a suggested provider for business-grade WireGuard tunnels with dedicated gateways and flat monthly billing. This tutorial covers manual WireGuard setup on macOS and Linux. You will install WireGuard tools, import a NordLayer peer configuration, bring up the tunnel, and test connectivity. The steps work with any WireGuard-compatible provider; replace NordLayer references with your provider's admin panel.

Steps

  1. Prepare accounts and access. Ensure you have an active NordLayer subscription and access to the admin panel. Ask your admin to create a dedicated gateway and generate a WireGuard peer configuration for each macOS or Linux device. You need the .conf file and the gateway endpoint details.
  2. Install WireGuard on macOS. Open the Mac App Store, search for WireGuard, and install the official client. Alternatively, if you use Homebrew, run brew install wireguard-tools for command-line use. For the GUI, import the .conf file via Add Tunnel > Import tunnel(s) from file.
  3. Install WireGuard on Linux. Use your package manager: sudo apt install wireguard on Debian/Ubuntu, sudo dnf install wireguard-tools on Fedora, or sudo pacman -S wireguard-tools on Arch. Confirm the installation with wg --version.
  4. Place the NordLayer config file. On Linux, move the NordLayer .conf file to /etc/wireguard/ with restricted permissions: sudo mv ~/Downloads/nordlayer-wg.conf /etc/wireguard/nordlayer.conf and sudo chmod 600 /etc/wireguard/nordlayer.conf. On macOS with wireguard-tools, you can use the same folder or a user-owned path.
  5. Review and adjust the config. Open the .conf file in a text editor. Confirm the [Interface] section includes PrivateKey and optionally Address and DNS. Confirm the [Peer] section includes the NordLayer gateway PublicKey, Endpoint, and AllowedIPs. For full tunnel, use AllowedIPs = 0.0.0.0/0, ::/0. For split tunnel, list only your internal subnets.
  6. Bring up the tunnel on Linux. Run sudo wg-quick up nordlayer (replace nordlayer with your config filename without .conf). Check the interface with sudo wg show. To enable at boot, run sudo systemctl enable wg-quick@nordlayer.
  7. Bring up the tunnel on macOS. In the WireGuard app, select the imported NordLayer tunnel and click Activate. If using wireguard-tools in Terminal, run sudo wg-quick up /path/to/nordlayer.conf. Approve any network permission prompts.
  8. Verify connectivity and DNS. Run curl ifconfig.me and confirm the public IP matches the NordLayer gateway or dedicated IP. Test internal DNS with nslookup internal.example.com or dig. If DNS fails, update the DNS = line in the config and restart the tunnel.
  9. Manage multiple gateways and team members. Create separate configs for each dedicated gateway if your team uses multiple locations. Give each device its own peer key. Revoke unused peers in the NordLayer admin panel. For macOS, keep tunnel names clear; for Linux, use one config file per gateway.
  10. Troubleshoot. If wg-quick up fails, check the config path, permissions, and Endpoint port. Use sudo journalctl -u wg-quick@nordlayer on Linux for logs. If the tunnel is up but traffic does not route, inspect AllowedIPs and local firewall rules. For handshake issues, verify the gateway public key and your system clock.