PUQ Mautic Skip to main content

01. Description

Overview

PUQVPNCP is a comprehensive VPN server management panel that supports four VPN protocols simultaneously: WireGuard, AmneziaWG, OpenVPN, and IKEv2/IPsec. It provides a modern web interface for managing VPN networks, clients, firewall rules, traffic control, and monitoring — all from a single dashboard.

The panel is designed for VPN service providers, hosting companies, and system administrators who need to manage hundreds or thousands of VPN clients across multiple networks with fine-grained control over bandwidth, routing, and anti-censorship security.


Key Features

Multi-Protocol Support

PUQVPNCP is unique in supporting four VPN protocols at once on the same server:

Protocol Technology Best For
WireGuard Modern kernel-level VPN Speed, low latency, mobile devices
AmneziaWG Obfuscated WireGuard fork Evading Deep Packet Inspection (DPI), strict censorship, ISP blocking
OpenVPN Battle-tested SSL/TLS VPN Compatibility, restrictive networks
IKEv2/IPsec Native OS support (strongSwan) iOS, macOS, Windows — native connection, no app required

Each client can connect via any enabled protocol using the same IP address. The panel automatically generates configuration files, QR codes, and certificates for each protocol.

Network Architecture

                   +--------------------------------------+
                   |          PUQVPNCP Server             |
                   |                                      |
Internet <---------|  Network A (10.0.0.0/24)             |
                   |    |-- WireGuard  (wg51820)          |
                   |    |-- AmneziaWG  (awg51821)         |
                   |    |-- OpenVPN    (ovpn1197)         |
                   |    +-- IKEv2      (strongSwan)       |
                   |                                      |
Upstream VPN <-----|  Network B (10.100.1.0/24)           |
(wgup0)            |    |-- WireGuard  (wg51822)          |
                   |    |-- AmneziaWG  (awg51823)         |
                   |    |-- OpenVPN    (ovpn1198)         |
                   |    +-- IKEv2      (strongSwan)       |
                   |                                      |
                   |  Network C (10.100.2.0/24)           |
                   |    +-- ...                           |
                   +--------------------------------------+
  • Networks define subnets, upstream routing, bandwidth limits, and protocol settings
  • Clients belong to a network and inherit its configuration
  • Upstreams allow routing network traffic through external WireGuard VPN servers

Upstream Tunnels

Route client traffic through external WireGuard VPN servers for:

  • Geographic IP rotation — clients appear from different countries
  • Multi-hop privacy — add an extra encryption layer
  • ISP bypass — route traffic through a clean IP when your server IP is blocked
  • Dedicated exit nodes — separate business and personal traffic

Per-Network Control

Each network operates independently with its own:

  • Subnet (IPv4 and IPv6)
  • VPN protocol settings and ports
  • Bandwidth limits (download/upload per network and per client)
  • Firewall rules (filter, NAT, DNAT, mangle)
  • Traffic control classes
  • Upstream (direct internet or WireGuard tunnel)
  • Custom routes pushed to clients
  • Port forwarding rules

Security & Access Control

  • Role-based access — permission groups with 36+ granular permissions
  • Multi-user — multiple administrators with different access levels
  • API tokens — create tokens with IP restrictions and expiration dates
  • Session security — IP-pinned sessions, login lockout protection
  • Automatic firewall — per-network isolation via ipset, per-client mangle rules

Operations

  • Traffic monitoring — per-client and per-network traffic statistics with daily breakdown
  • Real-time bandwidth — live traffic control with drops, overlimits, throughput
  • InfluxDB + Grafana — export metrics for advanced dashboards
  • Backups — automatic daily/hourly backups with FTP upload support
  • One-time links — generate self-service configuration links for end users
  • REST API — 170+ endpoints with full OpenAPI 3.0 documentation

Navigation

The web interface is organized into dropdown menus:

Networks menu Clients menu VPN Servers menu Settings menu
Networks Clients VPN Servers Settings
  • Networks — list, add networks, and manage peering
  • Clients — list, add clients, and view online connections
  • VPN Servers — configure WireGuard, AmneziaWG, OpenVPN, IKEv2, and Upstreams
  • Settings — networking, system, environment, firewall, DNS, monitoring, backups, OTL, users, permissions, API tokens, license

Technical Specifications

Component Details
OS Debian 12/13, Ubuntu 22.04+
Protocols WireGuard, AmneziaWG, OpenVPN 2.6+, IKEv2 (strongSwan 6.x)
Web Interface HTTPS with Let's Encrypt auto-SSL
API REST API, 170+ endpoints, OpenAPI 3.0
DNS Built-in bind9 DNS server
Firewall iptables/ip6tables with ipset
Monitoring rsyslog + telegraf + InfluxDB
Themes Light / Dark / Auto (system)
Max Clients 16,383 per server (across all networks)
Binary Single ~34MB Go binary, no runtime dependencies

Architecture Overview

+-----------------------------------------------------------------+
|                        Web Interface                            |
|                  (Bootstrap 5, jQuery, AJAX)                    |
+-----------------------------------------------------------------+
|                        REST API (Gin)                           |
|                   170+ endpoints, OpenAPI                       |
+-----------------------------------------------------------------+
|                       Core Engine (Go)                          |
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
|  |WireGuard | | AmneziaWG | | OpenVPN | | IKEv2   | |Firewall | |
|  |  (wg)    | |   (awg)   | |(openvpn)| |(strgSwn)| |(iptables)|
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
|  |Upstreams | |    DNS    | |   TC    | |Monitoring| |   OTL  | |
|  | (wgupN)  | |  (bind9)  | |  (tc)   | |(telegraf)| |(tokens)| |
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
+-----------------------------------------------------------------+
|                      Linux Kernel                               |
|   WireGuard / AmneziaWG module, Netfilter, TC, iproute2         |
+-----------------------------------------------------------------+

WHMCS Billing & Provisioning Automation

Selling VPN services or hosting packages? PUQ Software provides an official provisioning module for WHMCS:

PUQVPNCP WHMCS Provisioning Module

Key Capabilities:

  • Instant Automated Provisioning: Automatically provisions client VPN accounts upon invoice payment.
  • Lifecycle Management: Automated suspension on overdue invoices, unsuspension on payment, and termination on cancellation.
  • Bandwidth Shaping & Traffic Quotas: Synchronizes download/upload speed limits and traffic transfer limits directly from WHMCS product settings.
  • Client Area Self-Service: Customers can view credentials, download WireGuard and OpenVPN configurations, generate obfuscated AmneziaWG profiles, and scan QR codes right from their WHMCS client portal.
  • Multi-Server & Multi-Network: Route client accounts to specific PUQVPNCP servers and networks based on WHMCS product configuration.

License

PUQVPNCP requires an active license. Licenses can be purchased at:

https://puqcloud.com/store/puqvpncp

The license defines the maximum number of VPN clients and is validated periodically through the PUQ Cloud license server.