WireGuard setup for Windows

Choose a VPN protocol

Before you begin

You need an active Cloud1VPN server configured for WireGuard. Open My Servers and retrieve a .conf tunnel file or QR code before importing it into your client.

Get your WireGuard configuration

Windows setup

Connect with WireGuard

Use the official WireGuard client with the tunnel configuration generated for your Cloud1VPN server.

  1. Install WireGuard

    Download and run the official WireGuard installer, then open WireGuard from the Start menu.

    Open the official WireGuard installation page
  2. Download your tunnel configuration

    Open My Servers, choose the WireGuard server, and download its personal .conf file or display its QR code. Treat either format as a private credential.

  3. Import the tunnel

    In WireGuard, choose Import tunnel from file and select the .conf file downloaded from Cloud1VPN.

  4. Connect

    Activate the imported tunnel and approve any Windows request to create or enable the VPN connection.

  5. Verify your connection

    Confirm WireGuard shows a recent handshake, then check that your public IP matches the Cloud1VPN server.

    Open What's My IP?

Frequently Asked Questions

Windows WireGuard setup & troubleshooting

Should I use the .conf file or the QR code?

They contain the same private tunnel configuration. Use the .conf file when Windows supports file import; use the QR code when setting up a mobile device from a separate trusted screen. Never post either format or store it in a shared photo album.

Why will the WireGuard tunnel not import?

Choose Import tunnel from file and select the unmodified .conf file. If a tunnel with the same name already exists, remove the stale entry or give the new tunnel a unique name before importing it again. If the file was edited, renamed with an extra extension, or downloaded before a server rebuild, retrieve a fresh copy from My Servers.

What does “latest handshake” tell me?

No recent handshake means the client is not completing its encrypted exchange with the server; check the endpoint, server status, key freshness, and whether the current network blocks the connection. A recent handshake proves the peers can communicate, so failures after that point are more likely routing or DNS related.

Why did WireGuard stop working after a rebuild or relocation?

The old tunnel can contain an obsolete endpoint or key pair. Delete the old tunnel, download the new .conf file or QR code, and import it as a new connection instead of changing individual fields by hand.

WireGuard has a handshake, but websites do not load. What should I check?

A current handshake with no browsing usually points to routes, DNS, or another VPN taking priority. Disable competing VPN and proxy software, return custom DNS settings to automatic, reconnect, and then test both a website and What's My IP?.

Why is my normal public IP still visible?

The tunnel may be active without carrying the default internet route. Confirm you imported the complete Cloud1VPN configuration and that another tunnel is not preferred. After reconnecting, What's My IP? should report the address of the Cloud1VPN server for a full-tunnel profile.

Why does the tunnel disconnect after sleep or a network change?

Sleep, a Wi-Fi change, or another VPN client can replace the tunnel route. Disable the competing tunnel, toggle WireGuard once, and check the latest handshake time.

What should I send support for a WireGuard problem?

Include the Windows version, Cloud1VPN server name, failure time and timezone, whether a latest handshake appears, and the client error text. Never send the .conf file, QR code, private key, or account password.