How to Configure NordLayer WireGuard on macOS and Linux
Set up NordLayer WireGuard on macOS and Linux using WireGuard tools, import a dedicated gateway config, and verify secure team connectivity.
macOS
Linux
WireGuard
Overview
NordLayer WireGuard is a suggested provider for business-grade WireGuard tunnels with dedicated gateways and flat monthly billing. This tutorial covers manual WireGuard setup on macOS and Linux. You will install WireGuard tools, import a NordLayer peer configuration, bring up the tunnel, and test connectivity. The steps work with any WireGuard-compatible provider; replace NordLayer references with your provider's admin panel.
Steps
- Prepare accounts and access. Ensure you have an active NordLayer subscription and access to the admin panel. Ask your admin to create a dedicated gateway and generate a WireGuard peer configuration for each macOS or Linux device. You need the
.conffile and the gateway endpoint details. - Install WireGuard on macOS. Open the Mac App Store, search for WireGuard, and install the official client. Alternatively, if you use Homebrew, run
brew install wireguard-toolsfor command-line use. For the GUI, import the.conffile via Add Tunnel > Import tunnel(s) from file. - Install WireGuard on Linux. Use your package manager:
sudo apt install wireguardon Debian/Ubuntu,sudo dnf install wireguard-toolson Fedora, orsudo pacman -S wireguard-toolson Arch. Confirm the installation withwg --version. - Place the NordLayer config file. On Linux, move the NordLayer
.conffile to/etc/wireguard/with restricted permissions:sudo mv ~/Downloads/nordlayer-wg.conf /etc/wireguard/nordlayer.confandsudo chmod 600 /etc/wireguard/nordlayer.conf. On macOS withwireguard-tools, you can use the same folder or a user-owned path. - Review and adjust the config. Open the
.conffile in a text editor. Confirm the[Interface]section includesPrivateKeyand optionallyAddressandDNS. Confirm the[Peer]section includes the NordLayer gatewayPublicKey,Endpoint, andAllowedIPs. For full tunnel, useAllowedIPs = 0.0.0.0/0, ::/0. For split tunnel, list only your internal subnets. - Bring up the tunnel on Linux. Run
sudo wg-quick up nordlayer(replacenordlayerwith your config filename without.conf). Check the interface withsudo wg show. To enable at boot, runsudo systemctl enable wg-quick@nordlayer. - Bring up the tunnel on macOS. In the WireGuard app, select the imported NordLayer tunnel and click Activate. If using
wireguard-toolsin Terminal, runsudo wg-quick up /path/to/nordlayer.conf. Approve any network permission prompts. - Verify connectivity and DNS. Run
curl ifconfig.meand confirm the public IP matches the NordLayer gateway or dedicated IP. Test internal DNS withnslookup internal.example.comordig. If DNS fails, update theDNS =line in the config and restart the tunnel. - Manage multiple gateways and team members. Create separate configs for each dedicated gateway if your team uses multiple locations. Give each device its own peer key. Revoke unused peers in the NordLayer admin panel. For macOS, keep tunnel names clear; for Linux, use one config file per gateway.
- Troubleshoot. If
wg-quick upfails, check the config path, permissions, andEndpointport. Usesudo journalctl -u wg-quick@nordlayeron Linux for logs. If the tunnel is up but traffic does not route, inspectAllowedIPsand local firewall rules. For handshake issues, verify the gateway public key and your system clock.