Weft Start free trial

Blog · Guide · · 5 min read

Turn a small box in your office into a WireGuard concentrator

One Ubuntu machine becomes the place your laptops connect to, with the office's internet line as their way out. Nine steps from a bare box to a connected device, with screenshots.

A concentrator is the one place your remote devices connect to. Put it on a box you own, in the office, and three things follow: laptops reach the office network directly, their internet can leave through the office line (so anything that allow-lists your office IP just works), and there is no cloud VM to pay for or patch.

This guide takes a machine from a fresh Ubuntu install to a device connected through it. Every screenshot is from a real run of these steps; public addresses and one-time tokens in them are masked.

What you need

  • A machine that runs Ubuntu 24.04 LTS. A mini PC, a NUC or a spare 1U server, x86-64 or ARM64. It does not need to be big. For the screenshots we used a small cloud instance with 2 CPU cores and 2 GB of memory, standing in for the box; the steps on a mini PC are the same.
  • One network port connected to your office network, with internet access.
  • A way in from outside on UDP port 51820. Either the box has a public address, or you can add a port forward on your router: UDP 51820 to the box. Nothing else needs opening, not even SSH.
  • A Weft organisation. The free trial covers this whole guide.

1. Name the site

In the console, open Add a Linux node. Give the box a site id, choose already runs Ubuntu, and press Continue.

The Add a Linux node page with the site id office-hub entered and 'already runs Ubuntu' selected
The site id is how the box appears everywhere else in the console.

2. Run one command on the box

The console shows a single command. Copy it and run it on the machine, as a user who can sudo.

The console's 'Run this on the machine' card showing a curl command with a masked one-time enrolment token
The token in the command is single-use and expires after 24 hours. It is masked here.

The command checks the machine first (kernel WireGuard, the clock, the architecture, whether it can reach Weft), then installs WireGuard and FRR, installs the agent after checking it against its published checksum, and enrols. The box generates its own keys; only the public halves ever leave it. If you want to see the checks without changing anything, the card has a check the machine first command that does just that.

If the command stops with an error before it reaches Weft, the token has not been used. Fix what it names and run the same command again.

3. Check it has joined

Within a minute the box appears on the Overview with its agent version and a health of ok.

The Nodes table on the Overview showing office-hub, agent 0.158.0, role route reflector, health ok
This picture was taken after step 5, which is why its role already reads route reflector. Before that it says spoke.

4. Tell it which port faces the internet

Open Sites and then the new site. Under Uplinks, set WAN 1 port to the interface the box uses to reach the internet, and save. The list shows each interface with its address, and greys out the ones Weft itself created.

The Uplinks section with WAN 1 port set to ens5
On a mini PC the name will be something like enp1s0 or eno1. Leave WAN 2 alone unless the box has a second internet line.

5. Make it the hub

Further down the same page, under Route reflector, press Make a reflector. The first reflector in an organisation becomes the active hub: the place roaming devices connect to.

The Route reflector section showing the ACTIVE HUB badge
Add a second reflector later (another office, or a small cloud instance) and give it an address in step 6 too: then devices move to it by themselves if this one stops answering.

6. Tell devices where to find it

Open Settings and set client_hub_endpoint to the address devices should dial, with the port: your office's public IP, or a DNS name that points at it, followed by :51820.

The client_hub_endpoint setting with the value 203.0.113.10:51820
203.0.113.10 stands in for the real address here. If your office IP changes, use a DNS name instead: WireGuard looks it up when the tunnel starts.

If the box sits behind your router, this is when to add the port forward: UDP 51820 on the router to the box's address. Weft cannot see your router, so this is the one step it cannot check for you, and it is the first thing to look at if devices never connect.

7. Send devices' internet through the office

This step is optional. Skip it if you only want devices to reach the office network (a split tunnel).

For full tunnel, where everything a laptop sends goes through the office, the fabric needs a way out to the internet. Back on the site, under Egress node, press Make this the egress node. The box then takes devices' internet traffic out through its WAN port, translated to its own address.

The Egress node section showing 'originating default' after it was turned on
"Originating default" means the box is now the route to the internet for the whole organisation.

From the outside, a full-tunnel laptop's traffic now looks as if it comes from the office. That is useful when a supplier or a cloud service only accepts connections from your office IP.

8. Invite a device

Open Downloads. Under Invite a device, name the device, choose a tunnel, and press Invite.

The Invite a device form with device name sam-laptop and tunnel set to full, showing the full-tunnel warning
Choosing full tunnel shows what it means before you send anything.

You get a one-time invitation, valid for 24 hours. The person installs the Weft app for macOS or Windows from the same page, pastes the invitation and presses Join. The device makes its own key; no configuration file with a private key is ever sent. For a Linux machine, or anything that will not run the app, the Configuration only card on the same page produces a standard WireGuard file whose key is generated in your browser.

9. Check the device is connected

The Clients page shows each device, where it is connected and when it was last seen.

The Clients page showing test-linux connected 14 seconds ago via office-hub
"Connected via office-hub": the device is going through the box.

If something does not work

What you seeWhat it means
Inviting a device says the organisation has no hubStep 5 is not done: make the box a reflector.
Inviting a device says client_hub_endpoint gives no addressStep 6 is not done: set the address devices should dial.
"Has no uplink interface recorded" when making the egress nodeStep 4 is not done: choose the WAN 1 port.
The device says it is connecting but never connectsUDP 51820 is not reaching the box. Check the router's port forward, and any firewall in front of it.
A full-tunnel device connects but has no internetNothing is the way out: do step 7, or point the organisation at your own firewall (a perimeter) instead.

What you have now

One box in the office that your laptops connect to, that knows every route in your network, and that can be the office's internet exit for anyone working away. When you add a second office, enrol a box there the same way: the sites find each other, and devices keep connecting to the hub. The next guide does exactly that, then pulls the plug on the first office to see what remote staff go through. For the wider picture, see replacing the remote-access VPN and how Weft works.