Set up the VPN
Put a WireGuard configuration on the device with your phone, import it, and check that the tunnel is up.
You need a WireGuard server, and a client configuration made on it for the Cardputer, as you would make one for a phone: a .conf file.
- Get the
.confonto the phone (or a computer on the same Wi-Fi), and name itwg0.conf. - On the Cardputer, open Storage and press w; open the page on the phone (Move files with your phone).
- In the page, tap New folder, name it
vpn, go into it, and uploadwg0.conf. - On the Cardputer, press Back to stop sharing.
- Open Settings → VPN → Import /vpn/wg0.conf. You should see "Imported", and a question: delete the file. Say yes: the configuration is now in the device, and the file still holds the private key in clear.
- Switch VPN to On.
VPNappears in the Status Bar, and turns bright once the server has answered, usually within seconds. The page says "It is up". - To have it start by itself, switch on Start with Wi-Fi.
Check it
On the device, in the Shell: vpn status, then ifconfig (a vpn line, up) and ping the server's tunnel address. Or from another machine on the VPN, ping the Cardputer's tunnel address (the Address line of the file). More in When the network doesn't work.
If it stays dim
| The page says | Try |
|---|---|
| waiting for Wi-Fi | Connect to a network first |
| waiting for the clock | Give it a moment after Wi-Fi connects: the time comes from the network |
| looking up the server | The server's name doesn't resolve from this network |
| no answer yet | The server's address or port, a firewall on the way, or the keys: check the server's side has this client's public key |
What goes through it
Everything, if the file says AllowedIPs = 0.0.0.0/0; otherwise only the VPN's own subnet. To reach your home network behind the server, you need the first. See VPN.
The upload in step 3 is not encrypted, and the file holds a private key: do it on a network you trust, with a key made for this device.