diff --git a/docs/guides/wireguard/client.md b/docs/guides/wireguard/client.md index 3ad7960..d893819 100644 --- a/docs/guides/wireguard/client.md +++ b/docs/guides/wireguard/client.md @@ -52,7 +52,7 @@ After a restart, the server file should look like: ``` toml [Interface] Address = 10.100.0.1/24 -ListenPort = 44711 +ListenPort = 47111 SaveConfig = true PrivateKey = XYZ123456ABC= # PrivateKey will be different @@ -77,7 +77,7 @@ should tell you about your new client: interface: wg0 public key: XYZ123456ABC= ⬅ Your server's public key will be different private key: (hidden) - listening port: 44711 + listening port: 47111 peer: F+80gbmHVlOrU+es13S18oMEX2g= ⬅ Your peer's public key will be different preshared key: (hidden) @@ -111,7 +111,7 @@ Next, add your server as peer for this client: ``` toml [Peer] AllowedIPs = 10.100.0.0/24 -Endpoint = [your public IP or domain]:44711 +Endpoint = [your public IP or domain]:47111 PersistentKeepalive = 25 ``` @@ -165,7 +165,7 @@ on the server. It should show some traffic for your client if everything works: interface: wg0 public key: XYZ123456ABC= ⬅ Your server's public key will be different private key: (hidden) - listening port: 44711 + listening port: 47111 peer: F+80gbmHVlOrU+es13S18oMEX2g= ⬅ Your peer's public key will be different preshared key: (hidden) @@ -174,4 +174,10 @@ peer: F+80gbmHVlOrU+es13S18oMEX2g= ⬅ Your peer's public key will be differen transfer: 3.43 KiB received, 188 B sent ``` +## Test for DNS leaks + +You should run a DNS leak test on [www.dnsleaktest.com](https://www.dnsleaktest.com) to ensure your WireGuard tunnel does not leak DNS requests (so all are processed by your Pi-hole). The expected outcome is that you should only see DNS servers belonging to the upstream DNS destination you selected in Pi-hole. If you configured [Pi-hole as All-Around DNS Solution](../unbound.md), you should only see the public IP address of your WireGuard server and no other DNS server. + +See also [What is a DNS leak and why should I care?](https://www.dnsleaktest.com/what-is-a-dns-leak.html) (external link). + {!abbreviations.md!} diff --git a/docs/guides/wireguard/server.md b/docs/guides/wireguard/server.md index 7c2ff56..0955493 100644 --- a/docs/guides/wireguard/server.md +++ b/docs/guides/wireguard/server.md @@ -56,7 +56,7 @@ and put the following into it: ``` toml [Interface] Address = 10.100.0.1/24 -ListenPort = 44711 +ListenPort = 47111 SaveConfig = true ``` @@ -70,7 +70,7 @@ to copy the server's private key into your config file. ## Forward port -If the server is behind NAT, be sure to forward the specified port on which WireGuard will be running (for this example, `44711/UDP`) from the router to the WireGuard server. +If the server is behind NAT, be sure to forward the specified port on which WireGuard will be running (for this example, `47111/UDP`) from the router to the WireGuard server. ## Start the server @@ -116,7 +116,7 @@ The output should look like the following: interface: wg0 public key: XYZ123456ABC= ⬅ Your public key will be different private key: (hidden) - listening port: 44711 + listening port: 47111 ``` Your public key will be different to ours. This is expected (you just created your own key above).