Introduction
In this article, you will learn how to set up a manual NordVPN connection on Linux using the WireGuard® protocol. By downloading a WireGuard configuration file from your Nord Account and importing it with the WireGuard command-line tools, you can connect to a NordVPN server without the standard NordVPN application.
Before you start
- An active NordVPN subscription.
- You will need your NordVPN service credentials, not your standard Nord Account email and password.
Here's what to do
Step 1: Download and install WireGuard
- Go to the WireGuard downloads page and find the section for your Linux distribution.
- Open Terminal and run the listed WireGuard installation command.
- Once installed, the
wgandwg-quickcommand-line tools will be available for managing tunnels.
Step 2: Obtain your WireGuard configuration file
- Log in to your Nord Account and choose NordVPN.
- Scroll down to Advanced Settings and select Set up NordVPN manually.
- Use the dropdown menu to choose your preferred country.
- Find the server you want to use and, under Available protocols, select WireGuard.
- In the Setup configuration screen, select Download config.
- Save the downloaded .conf file somewhere you can find it, such as your Downloads folder.
Tip: You can repeat this step to download configuration files for multiple servers if you want to switch locations later.
Step 3: Import the configuration into WireGuard
- Open Terminal.
-
Move the downloaded configuration file into WireGuard's configuration
directory (
/etc/wireguard) and give it a short, recognizable name. -
Run the
ls /etc/wireguardcommand to ensure that the configuration file is present.
sudo mv ~/Downloads/us5830.nordvpn.com_wireguard.conf /etc/wireguard/nordvpn-us.conf
Step 4: Connect to the VPN
-
In Terminal, bring up the tunnel using the
sudo wg-quickcommand followed by the name you gave the file (without the .conf extension). - Within a few seconds, the terminal will confirm the interface is up. To verify the connection, run:
sudo wg-quick up nordvpn-us
sudo wg show
This will display the active tunnel along with your latest handshake and data transferred, indicating that the VPN connection is successful.
Additional tips
- To change locations, bring down your current tunnel with
sudo wg-quick down nordvpn-usand bring up a different imported tunnel, or download a new WireGuard configuration file following Step 2. - After the tunnel shows Active, you can verify your connection by checking your IP address status in the top bar on the NordVPN website.
WireGuard is a registered trademark of Jason A. Donenfeld.