Skip to content

Your own VPN server with WireGuard or OpenVPN

Connect your laptops and phones to a server you control. A private VPN gives your team one fixed IP address for allow lists, protects traffic on public Wi-Fi and reaches admin pages and apps you keep off the public internet. Run WireGuard or OpenVPN on a HyperDC VPS, preinstalled as an app option or installed with our guide.

  • WireGuard for speed, OpenVPN for TCP and older setups
  • One fixed IP address for your allow lists
  • Private access to admin pages and self-hosted apps
  • wg-easy web interface with QR codes for phones
Install
Distribution packages, or wg-easy with Docker
Stack
WireGuard in the Linux kernel · OpenVPN 2.7
Default ports51820/UDP is the port the WireGuard examples use, 1194/UDP is OpenVPN’s default; any free port works. wg-easy adds its web interface on 51821/TCP.
51820/UDP · 1194/UDP
Minimum
None published; a small VPS is enough
Exit address
Your server’s IP in the location you choose
Official docs
wireguard.com · openvpn.net

Protocols and tools

  • WireGuard
  • wg-easy
  • OpenVPN
  • Site-to-site
  • Split tunneling
  • Windows
  • macOS
  • Linux
  • iOS
  • Android

Facts from the project’s official website, documentation and repository, checked in October 2026.

VPN plans are being prepared

Tell us how many devices will connect and where they are, and our team will reply with the right server. Or start today on a Linux VPS and install VPN with our guide.

How big a server does a VPN need?

A VPN needs little memory. Encryption uses CPU and every byte passes the server, so the traffic you send decides the size.

How big a server does a VPN need?
Feature
Personal You and a few devices
Recommended Team Up to 50 devices
Office link Site-to-site links and many devices
vCPUVirtual processor cores of the server. 1 2 2–4
MemoryMemory for the app, its database and the operating system. 1 GB 1 GB 2 GB
DiskNVMe or SSD storage for the app, its data and local backups. 10 GB 10 GB 20 GB
TrafficEverything a device sends through the tunnel passes the server twice: in and out. Browsing and admin access A team’s daily work Constant traffic between sites
  • Personal

    You and a few devices

    vCPUVirtual processor cores of the server.
    1
    MemoryMemory for the app, its database and the operating system.
    1 GB
    DiskNVMe or SSD storage for the app, its data and local backups.
    10 GB
    TrafficEverything a device sends through the tunnel passes the server twice: in and out.
    Browsing and admin access
  • Recommended

    Team

    Up to 50 devices

    vCPUVirtual processor cores of the server.
    2
    MemoryMemory for the app, its database and the operating system.
    1 GB
    DiskNVMe or SSD storage for the app, its data and local backups.
    10 GB
    TrafficEverything a device sends through the tunnel passes the server twice: in and out.
    A team’s daily work
  • Office link

    Site-to-site links and many devices

    vCPUVirtual processor cores of the server.
    2–4
    MemoryMemory for the app, its database and the operating system.
    2 GB
    DiskNVMe or SSD storage for the app, its data and local backups.
    20 GB
    TrafficEverything a device sends through the tunnel passes the server twice: in and out.
    Constant traffic between sites

WireGuard and OpenVPN publish no hardware minimum. These starting points leave room for the operating system, a firewall and a web interface such as wg-easy.

What a VPN server of your own is for

A private VPN is about security and access: one trusted exit for your devices and one door to the services you keep private.

One fixed IP for allow lists

Let your team reach databases, admin panels and partner systems from one known address instead of changing home IPs.

Private access to your apps

Keep admin pages, DNS filters and internal tools reachable only through the tunnel, not from the whole internet.

WireGuard: fast and simple

A small, modern protocol built into the Linux kernel, with one key pair per device and fast reconnects on phones.

OpenVPN: when only TCP gets through

Run OpenVPN over TCP on port 443 for hotel or office networks that allow nothing but web traffic.

Dedicated IPv4 address

Linux and Windows VPS plans include a dedicated IPv4 address for your domain, your TLS certificate and your firewall rules.

Root access, your rules

Every Linux VPS, VDS and dedicated server comes with full root access: you choose the versions, the add-ons and the security settings.

Locations on three continents

Run your server in the United States, Europe or Asia, close to the people who use it. The order form estimates the latency from where you are to each location.

Preinstalled or with our guide

Choose the app as an option when you order and it is installed for you, or set it up yourself with our step-by-step guide.

Set up your VPN in four steps

Order the app preinstalled on your server, or install it yourself with our guide.

  1. Choose your server

    Pick a VPS, VDS or dedicated server in the size from the table above and the location closest to your users.

  2. Install WireGuard or OpenVPN

    Choose the VPN as an app option, or install WireGuard from your distribution’s packages, or wg-easy with Docker, using our guide.

  3. Open the port and secure the server

    Allow the VPN port (UDP 51820 or 1194) in the firewall, keep SSH key-only and serve the wg-easy interface over HTTPS.

  4. Add your devices

    Create one profile per device, scan the QR code with the WireGuard app or import the .conf or .ovpn file, and connect.

Step-by-step setup guides

Install, secure and update the app with our guides, written for current Ubuntu and Debian releases.

More guides

Related solutions

Self-Hosted App Hosting

Nextcloud, Immich, Jellyfin, Vaultwarden and more on your server.

Learn more

AdGuard Home and Pi-hole

Private DNS that blocks ads and trackers on every device.

Learn more

Vaultwarden

Bitwarden-compatible password server for families and teams.

Learn more

Linux VPS Hosting

KVM servers with full root access for any app stack.

Learn more

Data centers

Where our servers run and how to test the network.

Learn more

Secure a new Linux server

Users, SSH keys, firewall and updates before you install apps.

Learn more

Frequently asked questions

Still have a question? Send us a message and our team will reply by email.
WireGuard or OpenVPN: which should I choose?

Choose WireGuard for most setups: it is fast, has a small code base, is built into the Linux kernel since version 5.6 and reconnects quickly when phones change networks. Choose OpenVPN when a network lets only TCP through, when you need certificate-based user management, or when existing devices already use it.

Does my own VPN make me anonymous?

No. Your traffic leaves the internet from your server’s IP address, which belongs to your account with us. A private VPN protects traffic on untrusted networks and controls access to your services; it is not an anonymity service. Use it in line with the law and our terms of service.

Which ports do I have to open?

Only the VPN port: a UDP port for WireGuard, usually 51820, and 1194/UDP or 443/TCP for OpenVPN. wg-easy adds a web interface on its own port; keep it behind HTTPS and do not leave it open to everyone.

How many devices can connect?

There is no fixed limit in WireGuard or OpenVPN. Each device gets its own key or profile and its own address in the tunnel; CPU and bandwidth set the practical limit, so a small VPS serves a family and a larger one a whole team.

Can I send only some traffic through the VPN?

Yes. With split tunneling, list only the networks that should use the tunnel, such as your server’s private range, in AllowedIPs for WireGuard or as routes for OpenVPN. Everything else goes out through the device’s normal connection.

Can I connect my office network?

Yes. A site-to-site setup connects a router or a small Linux machine in the office to the VPN server and routes the office subnet through it. Plan non-overlapping private address ranges for every site first.

Do I need a web interface?

No, WireGuard is configured with a few text files. wg-easy adds a web interface for creating and removing devices and shows QR codes for phones, which helps when several people manage the VPN.

Ready to run your own VPN?

Tell us what you want to run and for how many people, and we will help you pick the right server.

Generate Password

Please confirm