A VPN does not have to be a monthly subscription to a company you know nothing about. With a small VPS in Kosovo and WireGuard, you can run your own private VPN in about ten minutes β one tunnel that your phone, laptop, tablet and home computer can all use, with a Kosovo IP address that belongs to you alone. And because YouTube does not show ads to viewers in Kosovo, every device connected to your tunnel can watch YouTube without ads. This guide explains why it is worth doing and walks you through the setup on Debian 13 step by step.
Why run your own VPN on a Kosovo VPS?
- Your server, your keys, your logs. Commercial VPN services ask you to trust their no-logs promise. On your own VPS, nobody else holds your keys or sees your traffic records.
- Your own Kosovo IP address. Every VPS comes with a dedicated public IPv4 address. Unlike a shared VPN, you are not sharing an address with thousands of strangers β so fewer CAPTCHAs and fewer blocked logins.
- Fast for users in the region. Thanks to local peering, traffic from Kosovo and the Balkans reaches the server over short network paths, so the tunnel adds very little delay.
- Works on every device. WireGuard has official apps for Android, iPhone, Windows, macOS and Linux. One server, as many devices as you like.
- Safe on public Wi-Fi. In hotels, airports and cafΓ©s, everything you do travels encrypted to your own server first.
- Reach Kosovo services while abroad. Banking, government portals and local sites see a Kosovo connection, wherever you are travelling.
- YouTube without ads. YouTube does not show ads in Kosovo, so everything you watch through the tunnel is ad-free β on every device.
- Room for more. The same VPS can also host a website, a game server or backups alongside the VPN.
Watch YouTube without ads
YouTube decides whether to show ads based on the country your connection comes from β and in Kosovo, YouTube currently does not show ads. When your phone, laptop or smart TV connects through your Kosovo VPN, YouTube sees a Kosovo connection, so you watch without pre-roll, mid-roll or banner ads, on every device and with no extra app or browser extension.
No ad blocker means nothing to break when YouTube updates its site, and it works the same in the YouTube app on phones and TVs as in the browser. Where YouTube shows ads is Googleβs decision and could change in the future.
What you need
- A VPS in Kosovo running Debian 13 β even the smallest plan is more than enough for a personal or family VPN
- The server's IP address and root password or SSH key (from your welcome email)
- An SSH client: Terminal on macOS and Linux, or Windows Terminal / PowerShell on Windows
- The free WireGuard app on each device you want to connect
Step 1 β Connect to your server and update it
Log in as root, replacing YOUR_SERVER_IP with your VPS address:
ssh root@YOUR_SERVER_IP
Then update the system and install WireGuard, the firewall tools it uses for sharing the connection, and a QR-code generator for phones:
apt update && apt full-upgrade -y
apt install -y wireguard iptables qrencode
Step 2 β Allow the server to forward traffic
By default Linux does not pass traffic between networks. Turn forwarding on, permanently:
echo "net.ipv4.ip_forward = 1" > /etc/sysctl.d/99-wireguard.conf
sysctl --system
Step 3 β Create the keys
WireGuard uses a key pair for the server and one for every device. This creates the server's keys and keys for your first device, a phone:
cd /etc/wireguard
umask 077
wg genkey | tee server.key | wg pubkey > server.pub
wg genkey | tee phone.key | wg pubkey > phone.pub
The .key files are private. Never share them or post them anywhere.
Step 4 β Create the server configuration
These commands detect your network interface and write the complete server config, filling in the keys automatically:
IFACE=$(ip route show default | awk '{print $5; exit}')
cat > /etc/wireguard/wg0.conf <<EOF
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = $(cat server.key)
PostUp = iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o $IFACE -j MASQUERADE; iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT
PostDown = iptables -t nat -D POSTROUTING -s 10.8.0.0/24 -o $IFACE -j MASQUERADE; iptables -D FORWARD -i wg0 -j ACCEPT; iptables -D FORWARD -o wg0 -j ACCEPT
[Peer]
# phone
PublicKey = $(cat phone.pub)
AllowedIPs = 10.8.0.2/32
EOF
Step 5 β Start the tunnel
systemctl enable --now wg-quick@wg0
wg show
wg show should list the wg0 interface, listening on port 51820, with one peer. The tunnel now starts automatically every time the server reboots.
If you run a firewall on the server, open WireGuard's port. For example, with UFW:
ufw allow 51820/udp
Step 6 β Create the config for your phone
SERVER_IP=$(hostname -I | awk '{print $1}')
cat > /etc/wireguard/phone.conf <<EOF
[Interface]
PrivateKey = $(cat phone.key)
Address = 10.8.0.2/32
DNS = 1.1.1.1
[Peer]
PublicKey = $(cat server.pub)
Endpoint = $SERVER_IP:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
EOF
AllowedIPs = 0.0.0.0/0, ::/0 sends all of the device's traffic through the tunnel, including IPv6, so nothing leaks around it.
Step 7 β Connect your device
Phone (Android or iPhone): show the config as a QR code in your terminal:
qrencode -t ansiutf8 < /etc/wireguard/phone.conf
Open the WireGuard app, tap + β Scan from QR code, scan it, and switch the tunnel on.
Computer (Windows, macOS, Linux): display the config with cat /etc/wireguard/phone.conf, copy the text, and in the WireGuard app choose Add empty tunnel (or import it as a .conf file) and paste it in. For a computer, create a separate config as shown in the next step rather than reusing the phone's.
To check it works, search for "what is my IP" on the device β it should show your VPS address in Kosovo.
Step 8 β Add more devices
Every device needs its own keys and its own address (10.8.0.3, 10.8.0.4 and so on). For a laptop:
cd /etc/wireguard
umask 077
wg genkey | tee laptop.key | wg pubkey > laptop.pub
cat >> wg0.conf <<EOF
[Peer]
# laptop
PublicKey = $(cat laptop.pub)
AllowedIPs = 10.8.0.3/32
EOF
systemctl restart wg-quick@wg0
Then repeat Step 6 with laptop.key, Address = 10.8.0.3/32 and a file name like laptop.conf, and import it on the laptop. To remove a device later, delete its [Peer] block from wg0.conf and restart.
Keep it secure
- Install automatic security updates:
apt install -y unattended-upgrades - Use SSH keys instead of a password for logging in to the server
- Give every device its own keys, so you can remove a lost phone without changing the others
- Never share
.keyfiles or the device.conffiles β anyone who has one can use your VPN
Troubleshooting
- The app says connected, but nothing loads: check that forwarding is on (
sysctl net.ipv4.ip_forwardshould print1) and thatwg showlists a recent handshake for the device. - No handshake at all: make sure UDP port 51820 is open in any firewall and that the
Endpointin the device config is your server's public IP. - Some sites fail over the tunnel: add
MTU = 1380under[Interface]in the device config and reconnect.
Frequently asked questions
Is running a VPN on my VPS allowed?
Yes. Personal and business VPNs are welcome on our network. Tor relays are not permitted under our Acceptable Use Policy, and as with everything you host, you are responsible for using the VPN lawfully.
How many devices can I connect?
As many as you like β each one just needs its own keys and address. A small VPS easily handles a family's or a small team's devices.
Can I use the same VPS for other things?
Yes. WireGuard uses very few resources, so the same server can also run a website, backups or other services.
Why WireGuard instead of OpenVPN?
WireGuard is faster, uses modern cryptography, reconnects instantly when your phone switches between Wi-Fi and mobile data, and its configuration fits on one screen.
Conclusion
With a Kosovo VPS and WireGuard, you get a private VPN that only you control: your own Kosovo IP, YouTube without ads, encrypted connections on any network, and fast speeds for users across the region β set up once and used from every device you own. Choose a VPS, install Debian 13 and follow the steps above β or message us on Telegram if you get stuck. To learn more about the benefits of hosting locally, read Why Buy a VPS in Kosovo?