Open a Protected URL Through WireGuard
One hosts line sends the site through your tunnel
Open a protected URL from your device
A protected URL lets your device in only when the request comes through the WireGuard tunnel. One line on your device sends the site's name to the server's private address.
Before you start
- Your device is in Devices, with On this server ticked on the server that serves the site, and its tunnel is active.
01 · Send the site through the tunnel
Add one line to your device's hosts file: the server's private address, then the site's name. The Device setup help button on the Protected URLs tab shows it already filled in. On macOS and Linux:
sudo sh -c 'echo "10.10.0.3 www.example.com" >> /etc/hosts'
On Windows, open Notepad as Administrator and add the same line to C:\Windows\System32\drivers\etc\hosts.
02 · Open the page
Open the protected URL as usual. The address bar and the certificate stay the same; the visit now travels through the tunnel.
While that line is there, the site opens on this device only with the tunnel active. Remove the line to reach it over the internet again.