{"id":533,"date":"2026-10-07T08:00:00","date_gmt":"2026-10-07T06:00:00","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/?page_id=533"},"modified":"2026-09-25T10:49:13","modified_gmt":"2026-09-25T08:49:13","slug":"raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling","status":"publish","type":"post","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/","title":{"rendered":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling"},"content":{"rendered":"<h2>Architectural Overview: WireGuard Kernel Routing and Split-Tunneling<\/h2>\n<p>Traditional VPN protocols such as OpenVPN or IPsec rely on userspace context switching and complex cryptographic handshakes, which introduce substantial CPU overhead and latency on single-board ARM computers like the Raspberry Pi. <strong>WireGuard<\/strong>, by contrast, operates directly inside the Linux kernel space using state-of-the-art cryptography (ChaCha20, Poly1305, Curve25519), enabling throughput exceeding 800 Mbps on Gigabit Ethernet interfaces with minimal CPU load.<\/p>\n<p>In a <strong>Split-Tunneling architecture<\/strong>, the Raspberry Pi functions as a hardened security gateway. Rather than routing all client internet traffic through the home network\u2014which bottlenecks mobile data speeds\u2014the tunnel selectively routes only specific destination subnets (e.g., local home lab resources under <code>192.168.10.0\/24<\/code>) through the encrypted WireGuard interface. Conversely, the gateway can also be configured to encrypt specific local LAN devices through an external privacy VPN provider while leaving general LAN traffic unaffected.<\/p>\n<figure class=\"lw-diagram\">\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/diagrams\/wireguard-split-tunnel-gateway-en.png\" width=\"1120\" height=\"560\" alt=\"Split-tunnel routing from the WireGuard client through the Raspberry Pi gateway into the home LAN, with direct internet traffic bypassing the tunnel\"><figcaption>Split tunnelling in the routing table: only the two networks listed under <code>AllowedIPs<\/code> travel through <code>wg0<\/code>. The gateway forwards them at kernel level and masquerades them onto <code>eth0<\/code>; all other traffic leaves the client directly.<\/figcaption><\/figure>\n<h2>Step-by-Step Implementation Guide<\/h2>\n<h3>Step 1: Enabling Linux Kernel IP Forwarding<\/h3>\n<p>To permit packet forwarding between the physical network interface (<code>eth0<\/code>) and the virtual WireGuard interface (<code>wg0<\/code>), IPv4 and IPv6 packet forwarding must be enabled permanently in the Linux kernel hierarchy:<\/p>\n<pre><code># \/etc\/sysctl.d\/99-wireguard-forwarding.conf\nnet.ipv4.ip_forward = 1\nnet.ipv6.conf.all.forwarding = 1\nnet.ipv4.conf.all.rp_filter = 1\nnet.ipv4.conf.default.rp_filter = 1<\/code><\/pre>\n<p>Apply the modified kernel parameters immediately without restarting the host:<\/p>\n<pre><code>sysctl --system<\/code><\/pre>\n<h3>Step 2: Cryptographic Key Generation and Package Installation<\/h3>\n<p>Install the WireGuard kernel tools and generate public\/private key pairs with restricted filesystem permissions:<\/p>\n<pre><code>apt update &amp;&amp; apt install -y wireguard wireguard-tools nftables\nmkdir -p \/etc\/wireguard &amp;&amp; cd \/etc\/wireguard\nchmod 700 \/etc\/wireguard\nwg genkey | tee server_private.key | wg pubkey &gt; server_public.key\nchmod 600 server_private.key<\/code><\/pre>\n<h3>Step 3: Configuring the Hardened Server Interface (wg0.conf)<\/h3>\n<p>The core configuration file defines the server listening port, subnet allocation, and integrated firewall routing rules. WireGuard\u2019s default UDP port (<code>51820<\/code>) is configured alongside strict `nftables` masquerading rules:<\/p>\n<pre><code># \/etc\/wireguard\/wg0.conf\n[Interface]\nAddress = 10.100.0.1\/24\nListenPort = 51820\nPrivateKey = &lt;SERVER_PRIVATE_KEY&gt;\n\n# Automated firewall masquerading via nftables\nPostUp = nft add table ip wireguard; nft add chain ip wireguard nat { type nat hook postrouting priority 100\\; policy accept\\; }; nft add rule ip wireguard nat oifname \"eth0\" masquerade\nPostDown = nft delete table ip wireguard\n\n# Example Split-Tunnel Client Peer Configuration\n[Peer]\nPublicKey = &lt;CLIENT_PUBLIC_KEY&gt;\nAllowedIPs = 10.100.0.2\/32<\/code><\/pre>\n<h3>Step 4: Client Split-Tunnel Routing Configuration<\/h3>\n<p>On the remote client device, the <code>AllowedIPs<\/code> directive controls whether the connection functions as a full tunnel or a split tunnel. Setting <code>AllowedIPs = 192.168.10.0\/24, 10.100.0.0\/24<\/code> forces only home network packets through the encrypted tunnel, while public web browsing continues directly over the client&#8217;s local internet connection:<\/p>\n<pre><code># Client-Side Configuration (Split-Tunneling Mode)\n[Interface]\nPrivateKey = &lt;CLIENT_PRIVATE_KEY&gt;\nAddress = 10.100.0.2\/24\nDNS = 192.168.10.1\n\n[Peer]\nPublicKey = &lt;SERVER_PUBLIC_KEY&gt;\nEndpoint = vpn.lukaswojcik.com:51820\nAllowedIPs = 192.168.10.0\/24, 10.100.0.0\/24\nPersistentKeepalive = 25<\/code><\/pre>\n<h3>Step 5: Quality Assurance and Throughput Validation<\/h3>\n<p>After starting the systemd service via <code>systemctl enable --now wg-quick@wg0<\/code>, verification must be conducted across three diagnostic vectors:<\/p>\n<ol>\n<li><strong>Handshake and Key Exchange Audit:<\/strong> Execute <code>wg show wg0<\/code> on the Raspberry Pi terminal to verify that active peers display recent cryptographic handshake timestamps and bidirectional transfer statistics.<\/li>\n<li><strong>Routing Table Verification:<\/strong> Inspect client routing tables (e.g., <code>ip route show<\/code>) to confirm that the default gateway remains unchanged while static routes for <code>192.168.10.0\/24<\/code> point strictly to the <code>wg0<\/code> interface.<\/li>\n<li><strong>Bandwidth and Latency Benchmark:<\/strong> Perform an internal <code>iperf3<\/code> throughput test between the remote client and an internal home lab server to ensure transmission speeds achieve network saturation without packet fragmentation.<\/li>\n<\/ol>\n<h2>Summary and Measurable Added Value<\/h2>\n<p><strong>What is achieved:<\/strong> Implementation of a hardened, kernel-space WireGuard VPN gateway on Raspberry Pi hardware configured with selective split-tunneling and automated firewall masquerading.<\/p>\n<p><strong>Resulting added value:<\/strong><\/p>\n<ul>\n<li><strong>Zero-Latency Remote Access:<\/strong> Internal home laboratory services, dashboards, and storage nodes become securely accessible from external networks without exposing internal ports to the public internet.<\/li>\n<li><strong>Optimized Bandwidth Consumption:<\/strong> Split-tunneling prevents unnecessary routing of external streaming or web traffic through home upload connections, maintaining maximum client download speeds.<\/li>\n<li><strong>Minimal Hardware Footprint:<\/strong> Kernel-level execution requires markedly less CPU time per transferred gigabyte than userspace protocols such as OpenVPN, leaving noticeably more system resources available for containerized services.<\/li>\n<\/ul>\n<div class=\"lw-faq\">\n<h2>Questions and answers<\/h2>\n<h3>Does a UDP port other than 51820 make the gateway less visible to scans?<\/h3>\n<p>Hardly. WireGuard does not answer any packet that lacks a valid handshake with a known key, so a port scan cannot distinguish the port from a filtered one, whatever its number. The hardening lies in the silence of the protocol, not in the port number, and 51820 is WireGuard&#8217;s usual default port anyway.<\/p>\n<h3>Can a client bypass the split tunnel and send all of its traffic through the home network?<\/h3>\n<p>Yes, because split tunneling is a decision made by the client. AllowedIPs on the client only determines which destinations it sends into the tunnel. If it enters 0.0.0.0\/0 there, all its traffic goes to the Raspberry Pi, and the Pi forwards it: forwarding is enabled, and the masquerading rule applies to everything leaving eth0, including the path to the internet.<\/p>\n<p>On the gateway, the configuration only restricts the source address: AllowedIPs = 10.100.0.2\/32 in the server file means that only packets with this source address are accepted from this peer. The line says nothing about destinations.<\/p>\n<p>If the gateway is to enforce the split tunnel, a filter chain on the forward hook is needed: allowing traffic from wg0 to the home network 192.168.10.0\/24 and replies to established connections, and dropping everything else coming from wg0. A table of the inet family covers IPv4 and IPv6 in a single chain.<\/p>\n<h3>What happens to name resolution on the client when the tunnel fails?<\/h3>\n<p>It fails along with it. With DNS = 192.168.10.1, the client asks a server on the home network, and that address lies within AllowedIPs. Every lookup therefore runs through the tunnel, including those for websites whose traffic otherwise goes straight to the internet. If the gateway cannot be reached, general traffic still flows directly, but names no longer resolve, and to the person using the device that looks like a complete outage.<\/p>\n<p>A second constraint concerns the network the client is currently on. If a hotel or guest network itself uses 192.168.10.0\/24, two routes compete for the same addresses, and depending on the routing the client loses access to either the home network or the local gateway. A less common subnet for the home network lowers this risk.<\/p>\n<\/div>\n<div class=\"lw-quellen\">\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.wireguard.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">WireGuard documentation<\/a><\/li>\n<li><a href=\"https:\/\/www.raspberrypi.com\/documentation\/computers\/os.html\" target=\"_blank\" rel=\"noopener noreferrer\">Raspberry Pi OS documentation<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Technical tutorial on deploying a secure, high-performance WireGuard VPN gateway on Raspberry Pi with selective split-tunneling and nftables firewall hardening.<\/p>\n","protected":false},"author":1,"featured_media":14085,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[92630],"tags":[91318,91321,91181,91219,91121,91141],"class_list":["post-533","post","type-post","status-publish","format-standard","hentry","category-tutorials-en-raspberry-pi","tag-firewall","tag-network-security","tag-raspberry-pi","tag-tutorial","tag-vpn","tag-wireguard"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling | Lukas Wojcik<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling | Lukas Wojcik\" \/>\n<meta property=\"og:description\" content=\"Technical tutorial on deploying a secure, high-performance WireGuard VPN gateway on Raspberry Pi with selective split-tunneling and nftables firewall hardening.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-07T06:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lukas Wojcik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lukas Wojcik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/\"},\"author\":{\"name\":\"Lukas Wojcik\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"headline\":\"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling\",\"datePublished\":\"2026-10-07T06:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/\"},\"wordCount\":917,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png\",\"keywords\":[\"Firewall\",\"Network Security\",\"Raspberry Pi\",\"Tutorial\",\"VPN\",\"WireGuard\"],\"articleSection\":[\"Tutorials\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/\",\"name\":\"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling | Lukas Wojcik\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png\",\"datePublished\":\"2026-10-07T06:00:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png\",\"width\":1200,\"height\":630,\"caption\":\"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"Lukas Wojcik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"Lukas Wojcik\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling | Lukas Wojcik","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/","og_locale":"en_US","og_type":"article","og_title":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling | Lukas Wojcik","og_description":"Technical tutorial on deploying a secure, high-performance WireGuard VPN gateway on Raspberry Pi with selective split-tunneling and nftables firewall hardening.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/","og_site_name":"Lukas Wojcik - Blog","article_published_time":"2026-10-07T06:00:00+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png","type":"image\/png"}],"author":"Lukas Wojcik","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lukas Wojcik","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#article","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/"},"author":{"name":"Lukas Wojcik","@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"headline":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling","datePublished":"2026-10-07T06:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/"},"wordCount":917,"commentCount":0,"publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png","keywords":["Firewall","Network Security","Raspberry Pi","Tutorial","VPN","WireGuard"],"articleSection":["Tutorials"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/","name":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling | Lukas Wojcik","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#primaryimage"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png","datePublished":"2026-10-07T06:00:00+00:00","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#primaryimage","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-533-raspberry-pi-hardened-wireguard-vpn--g.png","width":1200,"height":630,"caption":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/raspberry-pi-as-a-hardened-wireguard-vpn-gateway-with-split-tunneling\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Raspberry Pi as a Hardened WireGuard VPN Gateway with Split-Tunneling"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"Lukas Wojcik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"Lukas Wojcik"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=533"}],"version-history":[{"count":5,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/533\/revisions"}],"predecessor-version":[{"id":21690,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/533\/revisions\/21690"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media\/14085"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/categories?post=533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}