WireGuard "Handshake Did Not Complete": The Four Checks

Symptom

Interface up, no handshake in wg show, no traffic flows.

Root cause

Keys, endpoint, or MTU — almost always one of the three.

Fix, in order

1. Re-verify both keys (peer < > server)wg show # "latest handshake: never"
2. Endpoint must be server public IP + listen portEndpoint = 203.0.113.10:51820 # and UDP open in firewall
3. MTU: drop it and seeMTU = 1280 # if traffic connects but stalls

Prevent it coming back

PersistentKeepalive = 25 behind NAT; document each peer.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Shop network gear

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog