---
title: "用 WireGuard 打通异地局域网"
slug: "20261005124415"
date: "2026-03-11 21:05"
updated: "2026-10-05T12:44:07+08:00"
category: "笔记"
tags: ["VPN", "WireGuard", "网络"]
description: "相比 OpenVPN，WireGuard 配置简单、性能更好。这篇讲怎么把两个异地局域网连成一张网。"
url: https://blog.dayuai.com/20261005124415
---
## 为什么选 WireGuard

代码量小、密钥模型清晰、握手极快。一条配置就能建立加密隧道，不像 OpenVPN 那样要折腾证书体系。

## 核心思路

在两边各放一台「网关」机器运行 WireGuard，互为对端：

```ini
[Peer]
PublicKey = <对方公钥>
Endpoint = 公网IP:51820
AllowedIPs = 192.168.2.0/24
```

`AllowedIPs` 决定哪些流量走隧道。把对端局域网段写进去，两边局域网就能互相访问。

## 别忘了

- 网关要开启 IP 转发（`net.ipv4.ip_forward=1`）。
- NAT 后端设备回包路由要指回隧道接口。
- 防火墙放行 UDP 51820。
