Firewall Guide
From 2022 to 2025, we provided configuration files which could be imported into a pfSense firewall to replicate the recommended settings in the books. In 2026, those files became obsolete for two reasons. First, Proton VPN deprecated the certificates present within the files. Loading them today would likely refuse the connection to Proton VPN. Second, we now highly recommend the Wireguard protocol instead of OpenVPN. However, providing Wireguard configurations is tricky. There are so many variables for servers and different firewalls specify their ports uniquely behind the scenes. While we will leave the configuration files available here at the end of the guide, WE DO NOT recommend them for anything other than education. Instead, we strongly recommend building your own firewall with pfSense and Wireguard. This guide explains every step, but further details about why this is so important are available within Extreme Privacy 5th Edition. Let's begin!
Providing tutorials for technology can be exhausting. Things change quickly and there is no way to know the details of every reader's computing environment. What works great for me might not function at all for you. A single deviation in the steps, or a unique device on your network, can eliminate any success at replicating my setup.
I can think of no greater example than a home network. While the steps I have provided in the past for firewalls and Wi-Fi routers work for most people, it is the one topic which we encounter often in the complaint department. Recently, we offered abbreviated steps to configure Proton VPN with Wireguard in a pfSense firewall. We purposely did not repeat every technique from the book in order to limit the page count on the topic. For me, it was enough to get readers going in the right direction. This all caused some confusion. Some readers did not have the book. Some had IP address conflicts between the devices. A few got stuck on steps for pfSense 2.7.1 vs 2.8.1.
The following assumes you want to create a firewall which protects all devices on your network with a VPN. Those with 4 or 6 port hardware can optionally reserve a port for unprotected traffic to facilitate video streaming devices. Refer to the book for my reasons why this is so important. I believe everyone should migrate to these instructions instead of previous guides.
Install & Update pfSense Software
First, we need to download and install pfSense. This presents the first roadblock. In order to download the latest version of the Community Edition of pfSense, you must create an account at Netgate, provide an email address and password, then "order" the download. You must then provide a name, address, and telephone number. Only then will you be granted access to the "installer" file. I do not recommend this. Instead, we will download a publicly-available older version and update it internally within pfSense. If this option should disappear, you may have no other choice than playing their game after providing fictitious details. If you already have pfSense installed and want to start a new configuration, make a backup then restore to "Factory Default" and proceed to the next section.
• Navigate to https://atxfiles.netgate.com/mirror/downloads.
• If that site is down, use https://repo.ialab.dsu.edu/pfsense/
• Download "pfSense-CE-memstick-2.7.2-RELEASE-amd64.img.gz".
• Download the ".gz" file and decompress it (typically by double-clicking it).
• If your OS cannot decompress the file, download and install 7-Zip from 7-zip.org. Ensure you have a file with an .img extension, such as pfSense-CE-2.7.2-RELEASE--amd64.img.
• Download and install balenaEtcher from https://etcher.balena.io.
• Launch the program; select "Flash from file"; select the .img file; select the target USB drive; and execute the "Flash" option. Remove the USB device when finished.
Next, the following steps install pfSense to the Protectli Vault.
• Verify that the new hardware is off.
• Verify that a monitor and USB keyboard are connected directly to the Vault.
• Insert the USB install drive into another USB port on the firewall.
• Power the device and verify that it boots and begins the installation process.
If your Vault does not recognize the USB device and cannot boot into the installation, insert it into a different USB port. It may need priority over the USB keyboard. If that does not help, you must select the USB as a boot device. The procedure for this is different for every machine, but the Protectli Vault is fairly straight-forward.
• If you have coreboot, turn on the device and immediately press F11 on the keyboard repeatedly. Enter the number assigned to the USB device and strike the Enter key.
• If you have stock firmware, turn on the device and alternate pressing F11 then DEL on the keyboard repeatedly, one at a time. Enter the setup menu and use the right keyboard arrow to highlight "Boot"; use the down arrow to highlight "Hard drive priorities"; change Boot Option # 1 to the USB drive; and strike "F4" to save and exit.
You should be presented with an installation screen. Strike Enter to begin the process. Allow all default installation options, which should require you to strike the Enter key several times. During the default "ZFS (Auto) Configuration" screen, you may need to select the device's drive (often represented as "SSD" or "ada"). Highlight the appropriate drive for your installation and press the space bar to select it. Strike Enter to continue and select "Yes" to confirm you want to proceed. Choose "No" if prompted to open a shell and "Reboot" when complete.
After the device has completely rebooted (when you hear the startup tone), press the power button on the Protectli once to begin the shutdown process. This will take several seconds. Then, remove the USB flash drive, monitor, and keyboard connections. You are now ready to configure your new firewall operating system.
Once your firewall and computer are turned off, connect an ethernet cable from your computer to the LAN port of the Protectli Vault. This may require a USB to ethernet dongle if your laptop does not have an ethernet port. Connect an ethernet cable from your internet provider, such as your cable modem, to the WAN port of the Protectli device. The firewall must have an active internet connection for all tutorials to work correctly. This is because pfSense now needs to see both the local computer and the internet connection in order to complete all configurations. Once the cables are in place, turn on the firewall. Once the firewall beeps to announce it is ready (up to a minute), turn on your computer.
Make sure your computer has no internet access via any other cables or Wi-Fi. Note that this computer will have unfiltered internet via pfSense during configuration (no VPN). Navigate to 192.168.1.1 within a web browser (Firefox is preferred). Ignore any warnings about a certificate and click "Advanced" to allow the page to load. If necessary, click "Accept the Risk and Continue". Once you see the login portal, log in with the default username of "admin" and password of "pfsense". Accept all defaults within the setup process with "Next". Create a secure password when prompted. Click the various demands for "Next", "Close", "Reload" and "Finish" until you are at the home screen. Ignore any recommendations to update to pfSense Plus. This is unnecessary and inappropriate for our needs. Click "Accept" when presented with a trademark notice and "Close" to finish the onboarding.
You should now see the pfSense portal. We will spend a lot of time here. You should see a pending update. Apply all updates and allow the device to boot every time. This should take you to the most current version, which was 2.8.1 at the time of this writing. If you are not presented with this newer version, navigate to "System" > "Update" and select the current stable branch. Once you are on the latest version, proceed with the guide (however, it should work fine on older versions too).
Activate & Assign Additional Ports
If you purchased a 4-port or 6-port device, you should activate and assign the additional ports at this time by configuring the following modifications. If you purchased a 2-port option, skip these steps.
• Navigate to "Interfaces" then "Assignments" and click "Add" next to each port.
• Repeat until all ports have been added and "Add" is no longer present. Click "Save".
The following is split into multiple chunks, one for each OPT port. Again, this only applies to 4-port (first two) and 6-port (all four sections) devices.
• Navigate to "Interfaces" > "OPT1" and select "Enable interface".
• Change "IPv4 Configuration Type" to “Static IPv4".
• Enter an "IPv4 Address" of "192.168.2.1".
• Change "/32" to "/24"; click "Save"; then "Apply Changes".
• Navigate to "Firewall" then "Rules" and click "OPT1".
• Click "Add" (up arrow) and change the "Protocol" to "Any"
• Click "Display Advanced" and change the "Gateway" to "Wan_DHCP…".
• Click "Save" and "Apply Changes".
• Navigate to "Services" > "DHCP Server".
• Click "OPT1" and enable "Enable DHCP Server on OPT1 interface".
• Enter the "Range" as "From: 192.168.2.10 To: 192.168.2.250".
• Click "Save" then "Apply Changes".
• Navigate to "Interfaces" > "OPT2" and select "Enable interface".
• Change "IPv4 Configuration Type" to "Static IPv4".
• Enter an "IPv4 Address" of "192.168.3.1".
• Change "/32" to "/24"; click "Save"; then "Apply Changes".
• Navigate to "Firewall" then "Rules" and click "OPT2".
• Click "Add" (up arrow) and change the "Protocol" to "Any".
• Click "Display Advanced" and change the "Gateway" to "Wan_DHCP…".
• Click "Save" and "Apply Changes".
• Navigate to "Services" > "DHCP Server".
• Click "OPT2" and enable "Enable DHCP Server on OPT2 interface".
• Enter the "Range" as "From: 192.168.3.10 To: 192.168.3.250".
• Click "Save" then "Apply Changes".
• Navigate to "Interfaces" > "OPT3" and select "Enable interface".
• Change "IPv4 Configuration Type" to "Static IPv4".
• Enter an "IPv4 Address" of "192.168.4.1".
• Change "/32" to "/24"; click "Save"; then "Apply Changes".
• Navigate to "Firewall" then "Rules" and click "OPT3".
• Click "Add" (up arrow) and change the "Protocol" to "Any".
• Click "Display Advanced" and change the "Gateway" to "Wan_DHCP…".
• Click "Save" and "Apply Changes".
• Navigate to "Services" > "DHCP Server".
• Click "OPT3" and enable "Enable DHCP Server on OPT3 interface".
• Enter the "Range" as "From: 192.168.4.10 To: 192.168.4.250".
• Click "Save" then "Apply Changes".
• Navigate to "Interfaces" > "OPT4" and select "Enable interface".
• Change "IPv4 Configuration Type" to "Static IPv4".
• Enter an "IPv4 Address" of "192.168.5.1".
• Change "/32" to "/24"; click "Save"; then "Apply Changes".
• Navigate to "Firewall" then "Rules" and click "OPT4".
• Click "Add" (up arrow) and change the "Protocol" to "Any".
• Click "Display Advanced" and change the "Gateway" to "Wan_DHCP…".
• Click "Save" and "Apply Changes".
• Navigate to "Services" > "DHCP Server".
• Click "OPT4" and enable "Enable DHCP Server on OPT4 interface".
• Enter the "Range" as "From: 192.168.5.10 To: 192.168.5.250".
• Click "Save" then "Apply Changes".
The LAN port of your firewall has a default IP address scheme of 192.168.1.x. The OPT1 port now has a scheme of 192.168.2.x while the OPT2 port now has a scheme of 192.168.3.x. If you have the 6-port model, the OPT3 port now has a scheme of 192.168.4.x and the OPT4 port now has a scheme of 192.168.5.x. This segments each of the ports on your network and allows us to control how each port is protected. All of the ports are activated and ready for use, but none of them are protected by a VPN yet. Your internet connection is plugged into the WAN port, and your computer should still be plugged into the LAN port. If you were to plug any device into the OPT1 port, it would be issued an IP address in the range of 192.168.2.x and internet would work. Browsing to 192.168.2.1 from the OPT1 port would access pfSense, while connecting to 192.168.1.1 from the LAN port will do the same.
During this process, and throughout the remaining tutorials, you must allow pfSense to complete each step. This is especially important any time you need to "Apply Changes". Clicking this button forces pfSense to make several configuration changes. You must wait for these changes to complete before moving on to the next step. Otherwise, you will have failures. Always allow any pending processes to complete before navigating away from the menu screen. Make sure the pfSense tab within your browser has confirmed any change and it is not "reloading" before proceeding to the next step.
Configure pfSense Settings
These are some basic modifications which will make the device work optimally for our settings.
• Navigate to "System" > "Advanced" > "Networking".
• Select "KEA DHCP" and click "Save".
• Navigate to "System" > "Advanced" > "Miscellaneous".
• Enable "PowerD" and ensure "Hiadaptive" is chosen for each option.
• Scroll to the "Cryptographic & Thermal Hardware" section.
• Select "AES-NI CPU-based Acceleration" in the first drop-down menu.
• Select "Intel" from the "Thermal" menu.
• Click "Save".
• Navigate to "System" > "Advanced" > "Notifications".
• In the "E-mail" section, enable the "Disable SMTP" option.
• In the "Sounds" section, enable "Disable startup/shutdown beep" and click "Save".
• Navigate to "System" > "Advanced" > "Miscellaneous".
• Change "State Killing on Gateway Failure" to "Kill states for all gateways...".
• Enable the option next to "Skip rules when gateway is down" and click "Save".
Configure Proton VPN with WireGuard Protocol
We now recommend Wireguard for all pfSense VPN configurations. There is a lot of debate about which protocol is better. OpenVPN has been around much longer than WireGuard, but WireGuard has less bloated code than OpenVPN. WireGuard typically connects (and reconnects) faster than OpenVPN, but there are sometimes issues with the way a VPN provider flushes the connecting IP addresses in order to prevent logging (Proton has addressed this). WireGuard typically offers better VPN connection speed, but this may not be noticed by some people. As internet speed increases in homes, we should adopt this newer protocol. Log into Proton at https://account.protonvpn.com/downloads then conduct the following.
• Under "WireGuard Configuration", provide a name of "Firewall".
• Under "Select Platform", choose "Router".
• Under "Select a server to connect to", choose your desired country and server.
• Click the "Create" button then "Download" the file.
Return to your pfSense portal for the following.
• Navigate to "System" > "Package Manager" > "Available Packages".
• Search "WireGuard", click "Install" next to "WireGuard", then "Confirm".
• Allow the installation to complete.
• Navigate to "VPN" > "WireGuard" and click the "+Add Tunnel" button.
• Apply a "Description" of "ProtonTunnel" and "Listen Port" of "51820".
• Copy the "PrivateKey" data, which is presented in the Proton file which you downloaded, and paste it into the "Interface Keys" field.
• Click the "Public key" field and allow the public key to be generated.
• Click "Save Tunnel" the click "Peers" in the top menu.
• Click the "+Add Peer" button.
• Change the "Tunnel" to the "ProtonTunnel" option previously created.
• Apply a "Description" of "ProtonPeer".
• Disable the option next to "Dynamic Endpoint".
• Enter the "Endpoint" address and port from your file previously downloaded.
• Enter a value of "25" within "Keep Alive".
• Copy the "PublicKey" data, which is presented in the Proton file which you downloaded, and paste it into the "Public Key" field.
• Enter "0.0.0.0" within "Allowed IPs" and change "128" to "0".
• Click "Save Peer" the click "Settings" in the upper menu.
• Enable "Enable WireGuard" and click "Save" then "Apply Changes".
• Click "Status" in the upper menu and ensure a green "Up" connection.
• Select "Interfaces" and click "Assignments".
• Next to "tun_wg0" at the bottom, click "Add" then "Save".
• Click the new option at bottom, such as OPT1, OPT3, or OPT5.
• Enable "Enable Interface" and provide a "Description" of "ProtonInterface".
• Change "IPv4 Configuration Type" to "Static IPv4".
• Enter 10.2.0.2 into "IPv4 Address" and click "Save" and "Apply Changes".
• Navigate to "System" > "Routing" and click "Add".
• Change the Interface to "ProtonInterface".
• Change the name to "ProtonGateway".
• Change the Gateway to "10.2.0.1".
• Enable "Disable Gateway Monitoring Action".
• Select "Kill states using this gateway...".
• Click "Display Advanced" and check "Use non-local gateway".
• Click Save and Apply Changes.
• Navigate to "Interfaces" > "ProtonInterface".
• Change the IPv4 Upstream Gateway to "ProtonGateway".
• Enable "Block private networks and loopback addresses".
• Enable "Block Bogon Networks" and "Save" then "Apply changes".
Apply VPN to LAN port
Now that the VPN is configured and running, we must tell the LAN port to use it instead of unprotected internet.
• Navigate to "Firewall" > "NAT" > "Outbound".
• Select "Manual Outbound NAT rule generation".
• Click "Save" then "Apply Changes".
• Click the checkbox for every entry which has "ProtonInterface" to disable them.
• Click the checkbox for every entry which has "::1/28" to disable them.
• If desired, delete these disabled options as they are not needed.
• Click the pencil icon next to the option with a description similar to "Auto created rule LAN to WAN" which has the IP address of "192.168.1.0/24", change the "Interface" to "ProtonInterface", and click "Save".
• Click the pencil icon next to the option with a description similar to "Auto created rule for ISAKMP - LAN to WAN" which has the IP address of "192.168.1.0/24", and change the "Interface" to "ProtonInterface".
• Click "Save" then "Apply Changes".
• Navigate to "Firewall" > "Rules" > "LAN".
• Click the pencil icon (edit) next to "Default allow LAN to any rule".
• Click the "Display Advanced" option near the bottom.
• Change the "Gateway" to "ProtonGateway" and click "Save".
• Click the "Disable" icon next to "Default allow LAN IPv6 to any rule".
• Click "Apply Changes".
Apply VPN to OPT1
If you have a 4-port or 6-port device, you must either choose to protect the additional ports with a VPN connection or leave them open without protection for streaming devices. The following protects the OPT1 interface with a VPN.
• Navigate to "Firewall" > "Rules" > "OPT1".
• Click the pencil icon to edit the setting.
• If required, click the "Display Advanced" button.
• Change the "Gateway" to "ProtonGateway".
• Click "Save" and "Apply Changes".
• Navigate to "Firewall" > "NAT" > "Outbound".
• Click the pencil icon (edit) next to the option with a description similar to "Auto created rule - OPT1 to WAN".
• Change the "Interface" option of "WAN" to "ProtonInterface".
• Change the "Address Family" to "IPv4" and click "Save".
• Click the pencil icon (edit) next to the option with a description similar to "Auto created rule for ISAKMP - OPT1 to WAN" which has the "Source" IP address of your target port.
• Change the "Interface" option of "WAN" to "ProtonInterface".
• Click "Save" then "Apply Changes".
Apply VPN to OPT2
If you have a 4-port or 6-port device, you must either choose to protect the additional ports with a VPN connection or leave them open without protection for streaming devices. The following protects the OPT2 interface with a VPN. If desired, you could apply the upcoming OPT4 settings to this port to remove any VPN protection.
• Navigate to "Firewall" > "Rules" > "OPT2".
• Click the pencil icon to edit the setting.
• If required, click the "Display Advanced" button.
• Change the "Gateway" to "ProtonGateway".
• Click "Save" and "Apply Changes".
• Navigate to "Firewall" > "NAT" > "Outbound".
• Click the pencil icon (edit) next to the option with a description similar to "Auto created rule - OPT2 to WAN".
• Change the "Interface" option of "WAN" to "ProtonInterface".
• Change the "Address Family" to "IPv4" and click "Save".
• Click the pencil icon (edit) next to the option with a description similar to "Auto created rule for ISAKMP - OPT2 to WAN" which has the "Source" IP address of your target port.
• Change the "Interface" option of "WAN" to "ProtonInterface".
• Click "Save" then "Apply Changes".
Apply VPN to OPT3
If you have a 6-port device, you must either choose to protect the additional ports with a VPN connection or leave them open without protection for streaming devices. The following protects the OPT3 interface with a VPN. If desired, you could apply the upcoming OPT4 settings to this port to remove any VPN protection.
• Navigate to "Firewall" > "Rules" > "OPT3".
• Click the pencil icon to edit the setting.
• If required, click the "Display Advanced" button.
• Change the "Gateway" to "ProtonGateway".
• Click "Save" and "Apply Changes".
• Navigate to "Firewall" > "NAT" > "Outbound".
• Click the pencil icon (edit) next to the option with a description similar to "Auto created rule - OPT3 to WAN".
• Change the "Interface" option of "WAN" to "ProtonInterface".
• Change the "Address Family" to "IPv4" and click "Save".
• Click the pencil icon (edit) next to the option with a description similar to "Auto created rule for ISAKMP - OPT3 to WAN" which has the "Source" IP address of your target port.
• Change the "Interface" option of "WAN" to "ProtonInterface".
• Click "Save" then "Apply Changes".
Apply WAN to OPT4
If you have a 6-port device, you must either choose to protect the additional ports with a VPN connection or leave them open without protection for streaming devices. The following ensures OPT4 has no VPN protection. This could be applied to any other port desired.
• Navigate to "Firewall" > "Rules" > "OPT4".
• Click the pencil icon to edit the setting.
• If required, click the "Display Advanced" button.
• Ensure the "Gateway" is "WAN".
• Click "Save" and "Apply Changes".
• Navigate to "Firewall" > "NAT" > "Outbound".
• Click the pencil icon next to the "192.168.5.0/24" setting.
• Confirm the "Interface" is "WAN".
• Click "Save" and "Apply Changes".
Configure DNS (Option A-Extreme)
Next, you must choose a DNS provider to make sure that your ISP is not used for DNS queries. We also want secure encrypted DNS, so we must choose a provider which offer this option. While I prefer NextDNS on my computers and mobile devices, I do not need their custom filtering options as explained in a previous article in this issue. The DNS set on the pfSense will have no impact on the secure DNS set within my Firefox browser. Therefore, I currently recommend Cloudflare for DNS on the firewall for the minimal network needs outside of my computers, devices, and browsers. You can modify this to your own preference if desired.
• Navigate to "System" > "General Setup".
• Add 1.1.1.1 as the first DNS server.
• Enter "cloudflare-dns.com" as the first "DNS Hostname".
• Select "ProtonGateway".
• Click "Add DNS Server".
• Add 1.0.0.1 as the second DNS server.
• Enter "cloudflare-dns.com" as the second "DNS Hostname".
• Select "ProtonGateway".
• Disable "DNS server override".
• Change "DNS Resolution Behavior" to "Use local DNS, ignore remote DNS" and click "Save".
• Navigate to "Services" > "DNS Resolver".
• Within "Outgoing Network Interfaces", select "ProtonInterface".
• Enable "DNSSEC".
• Enable "DNS Query Forwarding".
• Enable "Use SSL/TLS for outgoing DNS Queries to Forwarding Servers".
• Click "Save" and "Apply Changes".
Configure DNS (Option B-Preferred)
From a purist privacy perspective, the previous settings make sense. All DNS traffic, even though already encrypted, also goes over an encrypted VPN connection. However, I have had issues with this in the past. In some scenarios, DNS cannot function properly this way because the VPN cannot connect right away at boot or if it drops out temporarily. This can be especially true if your VPN uses a domain instead of an IP address. If you are having issues maintaining a reliable internet connection to your firewall, change to the following. All DNS is still encrypted and your ISP cannot see your traffic or DNS queries. It simply knows you are using a different DNS provider. The following is how I currently set mine.
• Navigate to "System" > "General Setup".
• Add 1.1.1.1 as the first DNS server.
• Enter "cloudflare-dns.com" as the first "DNS Hostname".
• Select "WAN_".
• Click "Add DNS Server".
• Add 1.0.0.1 as the second DNS server.
• Enter "cloudflare-dns.com" as the second "DNS Hostname".
• Select "WAN_".
• Disable "DNS server override".
• Change "DNS Resolution Behavior" to "Use local DNS, ignore remote DNS" and click "Save".
• Navigate to "Services" > "DNS Resolver".
• Within "Outgoing Network Interfaces", select "All".
• Enable "DNSSEC".
• Enable "DNS Query Forwarding".
• Enable "Use SSL/TLS for outgoing DNS Queries to Forwarding Servers".
• Click "Save" and "Apply Changes".
Configure Home Screen
I prefer to modify my pfSense home screen, but this is a personal choice. I conduct the following.
• Navigate to the home screen and click the "+" in the upper-right.
• Add "Wireguard", "Gateways", "Disks", Thermal Sensors", and SMART Status.
• Reorganize the windows as desired and save.
Disable Logging
I prefer to disable all logging with the following steps.
• Navigate to "Status" > "System Logs" > "Settings".
• Click the "Reset" button and enable "Disable writing log".
• Disable all "Logging" "Preferences" and click "Save".
Test and Backup
Make sure your ports are using the VPN as desired. I test each with https://whatismyipaddress.com. When satisfied, make a backup.
• Navigate to "Diagnostics" > "Backup & Restore".
• Click the "Download configuration as XML" and save the file.
Disable All IPv6
This is also optional. On your home screen check the public IP address for the WAN interface. If it is a IPv4, such as 50.50.50.50, then you are not using IPv6 through your ISP or your VPN. You can disable all IPv6 if desired, which may prevent leaks.
• Navigate to "Services" > "DHCPv6 Server" > "LAN".
• Deselect "Enable".
• Click "Save" and "Apply Changes".
• Navigate to "Services" > "Router Advertisement" > "LAN".
• Change "Router Mode" to "Disabled" and click "Save".
• Navigate to "Interfaces" > "WAN".
• Change "IPv6 Configuration Type" to "None"
• Click "Save" and "Apply Changes".
• Navigate to "Interfaces" > "LAN".
• Change "IPv6 Configuration Type" to "None"
• Click "Save" and "Apply Changes".
• Navigate to "System" > "Routing".
• Edit the DHCP6 Gateway and select "Disable".
• Click "Save" and "Apply Changes".
• Navigate to "System" > "Routing".
• Change "Default gateway IPv6" to "None".
• Click "Save" and "Apply Changes".
• Navigate to "System" > "Routing".
• Delete the DHCP6 Gateway.
• Click "Apply Changes".
• Navigate to "System" > "Advanced" > "Networking".
• Uncheck "Allow IPv6" and click "Save.
Possess Proton VPN Server Alternatives
What happens if your chosen VPN server goes down? You should be prepared for that. Download a few additional Proton configuration files for different servers as previously explained. If ever needed, use the information within them to conduct the following.
• Navigate to "VPN" > "Wireguard" > "Edit Tunnel".
• Replace "Interface Key" with "Private Key" from the Proton file and allow new Public Key to generate.
• Click "Save" then "Peers", then edit the Peer.
• Replace "Endpoint" with the IP address in the Proton file.
• Replace "Public Key" with the "Public Key" from the Proton file.
• Stop and Restart Wireguard or simply reboot the device.
Hopefully, you are enjoying the Wireguard protocol for network-wide protection. You should notice more VPN stability and better speeds if you were maxed out of resources from OpenVPN. Be sure to log into your firewall and router on occasion and apply any pending updates. Make backups often!
OUTDATED 2025 Configuration Files
Updated March 2025. Follow the steps within Extreme Privacy: 5th Edition to apply these files.
Model: FW2B 2-port Protectli Vault
Configuration File: Proton VPN US Server
Service: Proton VPN
Firewall: Protectli
Firewall: Amazon
Model: FW4B 4-port Protectli Vault
Configuration File: Proton VPN US Server
Service: Proton VPN
Firewall: Protectli (FW4C)
Firewall: Amazon
Model: FW4C 4-port Protectli Vault
Configuration File: Proton VPN US Server
Service: Proton VPN
Firewall: Protectli
Firewall: Amazon
Model: FW6B/C/D/E 6-port Protectli Vault
Configuration File: Proton VPN US Server
Service: Proton VPN
Firewall: Protectli
Firewall: Amazon
OUTDATED 2022 Configuration Files
Updated August 2022. Follow the steps within Extreme Privacy: 4th Edition to apply these files.
Model: FW2B 2-port Protectli Vault
Configuration: Proton VPN US Server
Configuration: PIA US Server
Model: FW4B 4-port Protectli Vault
Configuration: Proton VPN US Server
Configuration: Proton VPN US Server (open "Netflix" port)
Configuration: PIA US Server
Configuration: PIA US Server (open "Netflix" port)
Model: FW6B 6-port Protectli Vault
Configuration: Proton VPN US Server
Configuration: Proton VPN US Server (open "Netflix" port)
Configuration: PIA US Server
Configuration: PIA US Server (open "Netflix" port)
Privacy Book
Our latest (5th Edition) book on Extreme Privacy is now available. Click HERE for details.