Skip to content

Multiple VPN Connections

You can keep more than one WireGuard tunnel up at the same time — two devices on two gateways, or the same gateway from two organizations — by giving each tunnel its own interface and its own device.

How the files are keyed

bnerd vpn up keeps two kinds of files under vpn.config-dir (default ~/.config/bnerd/wireguard):

  • <device>.key — the device's private key. One per device; it is the device's identity and is never sent anywhere.
  • <interface>.conf — the live tunnel configuration. One per interface; only one device can occupy an interface at a time.

So a second device on the same interface replaces that interface's .conf while both key files stay. Give every concurrent tunnel its own --interface.

Two devices, two interfaces

# Tunnel 1 on the default interface (device name defaults to this machine's hostname)
sudo bnerd vpn up

# Tunnel 2 on its own interface, with its own device name
sudo bnerd vpn up --device laptop-lab --interface bnerd1

# Both at once
sudo wg show

# Take one down; the device stays enrolled
sudo bnerd vpn down --interface bnerd1

Each device counts against its gateway's device limit until you revoke it:

bnerd vpn devices list
bnerd vpn devices revoke <device-id>

Two organizations

Gateways and devices are organization-scoped, and a token is bound to one organization. Use one config file per organization and point the CLI at it with --config:

~/.bnerd-org-a.yaml

api-url: https://api.bnerd.cloud
token: <org-A token, scope vpn_devices:write>
org-id: <org-A id>
vpn:
  interface: bnerd0

~/.bnerd-org-b.yaml

api-url: https://api.bnerd.cloud
token: <org-B token, scope vpn_devices:write>
org-id: <org-B id>
vpn:
  interface: bnerd1

sudo bnerd --config ~/.bnerd-org-a.yaml vpn up --device laptop-a
sudo bnerd --config ~/.bnerd-org-b.yaml vpn up --device laptop-b

bnerd --config ~/.bnerd-org-a.yaml vpn status
sudo bnerd --config ~/.bnerd-org-b.yaml vpn down

Shell aliases keep this short:

alias bnerd-a='bnerd --config ~/.bnerd-org-a.yaml'
alias bnerd-b='bnerd --config ~/.bnerd-org-b.yaml'

More than one ready gateway in an organization

bnerd vpn up picks the gateway only when the organization has exactly one ready WireGuard gateway. With several it refuses to guess and lists them; pass --gateway <id>:

sudo bnerd vpn up --gateway <gateway-id> --device laptop-site-a --interface bnerd2

Routing

Each tunnel routes exactly its gateway's service range (the AllowedIPs b'nerd issues with the device configuration). Two gateways of the same organization never share a range, so their tunnels do not overlap. If you connect to gateways of different organizations, check that their ranges differ before bringing both up:

grep AllowedIPs ~/.config/bnerd/wireguard/*.conf
ip route show

Troubleshooting

sudo wg show                    # every WireGuard interface and its last handshake
ip addr show bnerd0             # one interface
bnerd vpn status --interface bnerd1

Legacy: bnerd up --interface

The deprecated bnerd up is an alias of bnerd vpn up and takes the same --interface, --device and --gateway flags. See VPN Configuration.