Skip to content
beginner

How to Set Up NordLayer WireGuard on Windows for Team Remote Access

A step-by-step guide to installing WireGuard on Windows and connecting to a NordLayer dedicated gateway for secure team access.

Windows WireGuard Privacy/Anonymity

Overview

NordLayer WireGuard is a suggested provider for teams that need business-grade WireGuard tunnels. It uses dedicated gateways and flat monthly billing. This tutorial shows how to connect a Windows device to a NordLayer WireGuard gateway using the official WireGuard client. You will generate a peer configuration from NordLayer, import it into WireGuard for Windows, and verify the tunnel. The same workflow applies to any WireGuard-compatible provider; replace NordLayer with your provider where noted.

Steps

  1. Confirm prerequisites. You need an active NordLayer subscription, admin or member access to the NordLayer control panel, a Windows 10/11 device, and permission to install software. If you are not the admin, ask your NordLayer admin to create a dedicated gateway and a WireGuard peer for your device.
  2. Generate or download a WireGuard configuration. In the NordLayer admin panel, select the dedicated gateway you want to use and create a WireGuard peer for the Windows device. Download the .conf file. Keep it private; it contains the private key for that peer.
  3. Install WireGuard for Windows. Go to the official WireGuard site (wireguard.com/install) and download the Windows installer. Run it and complete the setup. Reboot if prompted.
  4. Import the NordLayer configuration. Open WireGuard. Click Add Tunnel > Import tunnel(s) from file. Select the .conf file you downloaded from NordLayer. The tunnel will appear in the list with the name from the config.
  5. Activate the tunnel. Click Activate on the NordLayer tunnel. The status should change to Active. If Windows asks for network profile permission, allow it for private or public networks as required by your team policy.
  6. Verify the connection. Open Command Prompt and run curl ifconfig.me (or visit an IP-check site). Confirm the public IP matches the NordLayer gateway or dedicated IP assigned to your peer. Then test access to an internal resource, such as a file share or intranet page.
  7. Configure DNS if needed. If your team uses internal DNS, confirm the DNS = line in the WireGuard config points to the correct resolver. If not, edit the tunnel in WireGuard and add the DNS server provided by your NordLayer admin.
  8. Repeat for each team device. Create a separate WireGuard peer for every user and device. Do not reuse one .conf file across multiple devices. Remove or revoke peers for departed team members in the NordLayer panel.
  9. Troubleshoot common issues. If the tunnel does not connect, check that the endpoint host and port are reachable, the system clock is correct, and the private key was not modified. If you can connect but cannot reach internal resources, review the AllowedIPs setting in the config. For split-tunnel access, AllowedIPs should list only the internal subnets; for full tunnel, use 0.0.0.0/0 and ::/0.