Skip to main content

How to set up WireGuard® on FRITZ!Box

To set up WireGuard on a FRITZ!Box router, you need to generate a WireGuard key pair in your Surfshark account, download the server configuration file, and then import it into your router's VPN settings. This guide will walk you through the complete process.

To proceed, you first need an active Surfshark subscription. You can find the available plans on Surfshark's pricing page.

Note: WireGuard® VPN support is implemented for current generation FRITZ!Box devices, starting from FRITZ!OS version 7.39 or higher. You can check your router's firmware by going to FRITZ!Box official website, or by navigating to the Dashboard section on your router's web interface.

 

Credentials and server selection

Before setting up the router, you will need to obtain the credentials for the manual setup and select a server to connect to.

 

Get your WireGuard credentials
 

NOTE: These are not your regular credentials, such as your email and password.
 

  1. Head to the Surfshark login page and log in. Then, click on VPN -> manual setup.

    Surfshark dashboard with VPN then Manual setup selected
     
  2. Select set up manually.

    Manual setup page with Set up manually highlighted
     
  3. Choose the WireGuard protocol.

    Choose a protocol page with WireGuard highlighted under Router
     
  4. Once there, select I don't have a key pair.

    WireGuard Connect key pair with I don't have a key pair highlighted

    NOTE: If you have already created a key pair, simply press I have a key pair, and enter your public key.
     
  5. Enter a name for the keypair, and click next.

    WireGuard key pair name field filled with Test and Next
     
  6. Click generate new key pair.

    WireGuard credentials with Generate a new key pair
     
  7. You will be able to see a public and a private key pair. Make sure to save both of them.

    Generated WireGuard public and private keys with Choose a location

 

Choose a Surfshark VPN server

  1. Head to the Locations tab and locate the server that you wish to connect to.

    WireGuard Locations tab listing servers with download icons
     
  2. Click on the download icon to the right of the server name.

    WireGuard Locations with the Fastest server download icon highlighted
     
  3. Click on the download icon.

    Belgium Brussels config sheet with Download WireGuard configuration files highlighted

 

Configure the interface

  1. Log in to your FRITZ!Box router’s interface. You can access it by entering your router's default gateway IP address into your browser's URL bar. By default, it is usually http://192.168.178.1. If that does not work, use the emergency IP http://169.254.1.1

    Alternatively, you can enter this address: http://fritz.box
    Browser address bar showing http://fritz.box
    Browser address bar showing http://192.168.178.1
    Browser address bar showing http://169.254.1.1

     
  2. If you haven’t done so before, you will have to set up your MyFRITZ! address. Follow these steps:
    1) Click Internet in the FRITZ!Box user interface.
    2) Click on MyFRITZ! Account in the Internet menu.
    3) Enter your email address in the Your email address field.
    4) Click Apply. Now MyFRITZ! will send you an email with the confirmation link to confirm your FRITZ!Box account.
    5) Open the email you received from MyFRITZ!
    6) Click the Register Your FRITZ!Box button in the email.
    FRITZ!Box Internet MyFRITZ! Account registration page

     
  3. Now, we will configure Surfshark’s WireGuard VPN tunnel. To do so, in the router's web panel, in the Internet section, click on Permit Access.
    FRITZ!Box sidebar with Permit Access highlighted under Internet

     
  4. Click the VPN (WireGuard) tab.
    Permit Access page with the VPN (WireGuard) tab highlighted

     
  5. Click the Add Connection button.
    VPN (WireGuard) tab with Add Connection highlighted

     
  6. Click "User-defined setup" and then "Next".

     
  7. You will get a prompt: Has this WireGuard connection already been set up at the remote connection? Click Yes.
    User-defined settings asking if WireGuard is already set up, with Yes selected

     
  8. Click on Next.
    User-defined settings with Next highlighted

     
  9. Enter a name for the connection in the Name of the WireGuard connection field (for example, Surfshark).
    Import WireGuard connection form with the name field highlighted

     
  10. Click the Choose File or Browse... button.
    Import WireGuard connection form with Choose File highlighted

     
  11. Select the settings file for the WireGuard connection that you downloaded from Surfshark and click Open. After, enable the option Send all network traffic via the VPN connection.
    Advanced settings with Send all IPv4 network traffic via the VPN connection checked

    NOTE: If only certain devices should be able to access the internet via Surfshark VPN, enable the option Only certain devices in the home network are to be accessible over this WireGuard connection,and select the corresponding devices. This option is available only on some FRITZ!Box models.

     
  12. Click the Finish button.

     
  13. If asked to do so, confirm that the procedure may be executed and click OK to complete it.
    FRITZ!Box import form with a Surfshark config file chosen and Finish

 

Test your VPN connection

We always recommend checking if Surfshark VPN is working after setting it up for the first time. You can easily do it by performing Surfshark IP leak test and a DNS leak test. For your convenience, both are available on our website.




 

You may also be interested in:

Was this article helpful?
Thank you for your feedback!