How to set up a manual NordVPN connection on Linux using WireGuard

Introduction

In this article, you will learn how to set up a manual NordVPN connection on Linux using the WireGuard® protocol. By downloading a WireGuard configuration file from your Nord Account and importing it with the WireGuard command-line tools, you can connect to a NordVPN server without the standard NordVPN application.

Before you start

Here's what to do

Step 1: Download and install WireGuard

  1. Go to the WireGuard downloads page and find the section for your Linux distribution.
  2. Open Terminal and run the listed WireGuard installation command.
  3. Once installed, the wg and wg-quick command-line tools will be available for managing tunnels.

Step 2: Obtain your WireGuard configuration file

  1. Log in to your Nord Account and choose NordVPN.
  2. Scroll down to Advanced Settings and select Set up NordVPN manually.
  3. Use the dropdown menu to choose your preferred country.
  4. Find the server you want to use and, under Available protocols, select WireGuard.
  5. In the Setup configuration screen, select Download config.
  6. Save the downloaded .conf file somewhere you can find it, such as your Downloads folder.

Tip: You can repeat this step to download configuration files for multiple servers if you want to switch locations later.

Step 3: Import the configuration into WireGuard

  1. Open Terminal.
  2. Move the downloaded configuration file into WireGuard's configuration directory (/etc/wireguard) and give it a short, recognizable name.
  3. sudo mv ~/Downloads/us5830.nordvpn.com_wireguard.conf /etc/wireguard/nordvpn-us.conf
  4. Run the ls /etc/wireguard command to ensure that the configuration file is present.

Step 4: Connect to the VPN

  1. In Terminal, bring up the tunnel using the sudo wg-quickcommand followed by the name you gave the file (without the .conf extension).
  2. sudo wg-quick up nordvpn-us
  3. Within a few seconds, the terminal will confirm the interface is up. To verify the connection, run:
  4. sudo wg show

    This will display the active tunnel along with your latest handshake and data transferred, indicating that the VPN connection is successful.

Additional tips

  • To change locations, bring down your current tunnel with sudo wg-quick down nordvpn-us and bring up a different imported tunnel, or download a new WireGuard configuration file following Step 2.
  • After the tunnel shows Active, you can verify your connection by checking your IP address status in the top bar on the NordVPN website.

WireGuard is a registered trademark of Jason A. Donenfeld.

Also available in:
Was this article helpful?

Still having issues?

  • Live chat

  • Email form

By clicking “Chat with support”, you agree to our Terms of Service and acknowledge our Privacy Policy. Chat functionality relies on cookies. By starting the chat, you agree to their use. Learn more in our Cookie Policy.