How to Build Your Own Self-Hosted VPN
Commercial VPN services sell you a slice of someone else's servers. If you want to know where your traffic goes, who can see it, and what it costs at scale, running your own is the direct answer. You can start with one small VPS and grow into several regions with failover.
This guide builds a self-hosted VPN with Pangolin, from a single server to a multi-region deployment that stays up when a machine dies.
Two Kinds of VPN in One
Pangolin covers two jobs that people usually call a VPN.
By default it is a split tunnel VPN. Clients reach your private resources, such as servers, databases, and home machines, and everything else goes out over the device's normal internet connection. This is the right setup for secure access to a company or home network.
With an exit node, a client sends all of its internet traffic through a site as well. Websites see the exit node's IP address instead of yours. This is what most people mean by a personal VPN: safer public Wi-Fi, or access to services that only work from a particular country.
You can use either one, or both on the same network.
What You Need
- A domain name for the Pangolin dashboard.
- A Linux VPS with a public IP address for the Pangolin server. See Choosing a VPS.
- One machine in each location you want traffic to exit from. These can be small VPS instances, a Raspberry Pi at home, or a cloud instance in another region.
- The Pangolin client on the devices that will connect.
Step 1: Self-Host the Pangolin Server
Follow the quick install on your VPS. It sets up Pangolin, Gerbil, and Traefik with Docker Compose in a few minutes. When it finishes you have a dashboard at your own domain and an organization to work in.
The DNS and networking page lists the ports the server needs open.
Step 2: Deploy an Exit Node Site
An exit node is a site, so you deploy it like any other. Traffic leaves to the internet from wherever the site runs.
- In the dashboard, create a site.
- Run the site connector on the machine that should be your exit point. See Install Sites. This could also be the Pangolin server.
The site connects outbound to your Pangolin server, so the exit machine does not need inbound ports opened for clients. Use one machine for now and add more in step 5.
Step 3: Create the Exit Node Resource
- Create a new private resource and set the mode to Exit Node.
- Select the site you deployed.
- Choose which roles, users, and machine clients can use it. If its just you - you can leave it blank.
An exit node has no destination, since it routes all traffic through the default routes (0.0.0.0/0 and ::/0). All TCP and UDP ports and ICMP are allowed.
Step 4: Connect a Device
Install the Pangolin client on your laptop or phone and log in to your server.
On macOS, Windows, iOS, and Android, open the app, go to the exit node section, and choose the node. On the CLI:
pangolin select exit-node
To check that it works, look up your public IP address in a browser. It should show the exit machine's address. To stop using the exit node, select None.
By default your other Pangolin resources stay reachable while the exit node is on. To send everything through the exit node, enable Exit Nodes Take Precedence Over Resources.
Step 5: Add More Regions
To exit from several countries, deploy a site in each region and add them all to the same exit node resource. With multiple sites selected, the client picks the best one by latency. If you want to choose a specific country, create one exit node resource per site and name each after its location, such as exit-frankfurt and exit-singapore.
Budget VPS providers have locations in most regions, and a 1 vCPU instance handles a lot of VPN traffic. Start small and check the bandwidth limits before you pick a plan.
The exit site's provider determines the IP address that services see, and some streaming and banking services block known datacenter ranges. A site on a residential connection, such as a Raspberry Pi at home, gives you a residential address, at the cost of the home connection's upload speed.
Keeping It Available
With several sites on one exit node resource, a client fails over to another online site when one goes down. Failover takes a few seconds while the site is marked offline and the change reaches clients. See Multi-site Routing and High Availability. If a region matters to you, run two sites there on different machines or providers.
Access Control and Logging
A self-hosted VPN is only as safe as its access rules. On the exit node resource, give access to specific roles or machine clients instead of everyone, and block or archive devices you no longer need. See archiving and blocking.
Network connection logs record the traffic that crosses the exit node. They are available on Enterprise Edition and Pangolin Cloud.
FAQ
Is this the same as running WireGuard or OpenVPN myself?
Pangolin uses WireGuard for its tunnels. What you would otherwise do by hand is generate keys, distribute configs, open ports, and manage users on each server. Pangolin handles that from one dashboard and adds identity-based access, NAT traversal, and multi-site routing.
Do I need to open ports on the exit machine?
No. Sites connect outbound. The Pangolin server does need its own ports open. See DNS and networking.
Can I use it on my phone?
Yes. The iOS and Android apps support exit nodes.
Can I connect an office as well?
Yes. The same server can link branch offices and cloud networks. See Branch Office Networking and Cloud Backhaul.
Related Reading
- Exit Nodes docs
- Highly Available VPN
- Pangolin vs. Tailscale
- Pangolin Remote Nodes: Cloud Control Plane & Failover
Learn More
Self-host Pangolin to build your own, or get started on Pangolin Cloud for a managed control plane.
Pangolin is an open-source Secure Access Service Edge (SASE) platform built on WireGuard® that unifies modern networking and security for teams connecting to apps, infrastructure, and AI workloads. Designed as an open, self-hostable alternative to complex legacy suites, Pangolin brings together a zero-trust VPN, zero-trust reverse proxy, privileged access management, and an identity-aware AI gateway under a single identity and policy model. Whether deployed on-premises using a lightweight user-space connector or managed via Pangolin Cloud, it gives organizations transparent, auditable, and frictionless control over their entire digital footprint.
Keep reading
- Branch Office Networking with Pangolin
Branch Office Networking with PangolinHow to connect branch offices, stores, and factories to a cloud network or to each other with Pangolin subnet routers, using a hub and spoke model with no inbound firewall rules.
- Highly Available Identity-Aware Proxy: Self-Hosting Zero Trust Without a Single Point of Failure
Highly Available Identity-Aware Proxy: Self-Hosting Zero Trust Without a Single Point of FailureWhy an identity-aware proxy is harder to make highly available than a normal load balancer, and how to self-host one that stays up without sending traffic through someone else's cloud.
- Highly Available VPN: How to Remove the Single Point of Failure
Highly Available VPN: How to Remove the Single Point of FailureWhat makes a VPN highly available, why most self-hosted VPNs are a single point of failure, and three ways to get real HA remote access with Pangolin.