Set up Veystrix on Linux
Two commands if you use the terminal, or NetworkManager if you prefer clicking.
Sign in to download your configuration file, or see plans.
Before you start: sign in at your account, choose a location and download your configuration file.
Install WireGuard
```
Debian / Ubuntu
sudo apt install wireguard
Fedora
sudo dnf install wireguard-tools
Arch
sudo pacman -S wireguard-tools ```
The quick way: wg-quick
`` sudo cp ~/Downloads/veystrix-*.conf /etc/wireguard/veystrix.conf sudo chmod 600 /etc/wireguard/veystrix.conf sudo wg-quick up veystrix ``
To disconnect:
`` sudo wg-quick down veystrix ``
To bring it up on every boot:
`` sudo systemctl enable --now wg-quick@veystrix ``
Check the tunnel state at any time with sudo wg show.
Check it worked
`` curl https://www.veystrix.net/tools/ip ``
Or open veystrix.net/tools/ip in a browser. It should report our network and the country you chose.
If you prefer NetworkManager
`` sudo apt install network-manager-gnome # if not already present nmcli connection import type wireguard file ~/Downloads/veystrix-*.conf ``
It then appears in the desktop network menu like any other connection, with a normal on/off toggle.
A kill switch
wg-quick can add firewall rules that block traffic outside the tunnel. Add this to the [Interface] section of your config, before bringing it up:
`` PostUp = iptables -I OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT PreDown = iptables -D OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT ``
Test it on a machine you are sitting at rather than one you reach over SSH. A firewall rule that blocks everything is easy to write and awkward to undo remotely.
If it does not work
wg-quick: command not found — install wireguard-tools rather than wireguard.
RTNETLINK answers: Operation not supported — your kernel lacks the WireGuard module. Kernels from 5.6 onwards include it; older ones need wireguard-dkms.
DNS does not resolve once connected — install openresolv or systemd-resolved. wg-quick needs one of them to apply the DNS setting in the config.
Name resolution leaks — check resolvectl status shows our DNS on the veystrix interface, not your router's.
One thing worth knowing
The config contains your private key. chmod 600 it, as above, and delete the copy in ~/Downloads.