01. Description
Overview
PUQVPNCP is a comprehensive VPN server management panel that supports four VPN protocols simultaneously: WireGuard, AmneziaWG, OpenVPN, and IKEv2/IPsec. It provides a modern web interface for managing VPN networks, clients, firewall rules, traffic control, and monitoring — all from a single dashboard.
The panel is designed for VPN service providers, hosting companies, and system administrators who need to manage hundreds or thousands of VPN clients across multiple networks with fine-grained control over bandwidth, routing, and anti-censorship security.
Key Features
Multi-Protocol Support
PUQVPNCP is unique in supporting four VPN protocols at once on the same server:
| Protocol | Technology | Best For |
|---|---|---|
| WireGuard | Modern kernel-level VPN | Speed, low latency, mobile devices |
| AmneziaWG | Obfuscated WireGuard fork | Evading Deep Packet Inspection (DPI), strict censorship, ISP blocking |
| OpenVPN | Battle-tested SSL/TLS VPN | Compatibility, restrictive networks |
| IKEv2/IPsec | Native OS support (strongSwan) | iOS, macOS, Windows — native connection, no app required |
Each client can connect via any enabled protocol using the same IP address. The panel automatically generates configuration files, QR codes, and certificates for each protocol.
Network Architecture
+--------------------------------------+
| PUQVPNCP Server |
| |
Internet <---------| Network A (10.0.0.0/24) |
| |-- WireGuard (wg51820) |
| |-- AmneziaWG (awg51821) |
| |-- OpenVPN (ovpn1197) |
| +-- IKEv2 (strongSwan) |
| |
Upstream VPN <-----| Network B (10.100.1.0/24) |
(wgup0) | |-- WireGuard (wg51822) |
| |-- AmneziaWG (awg51823) |
| |-- OpenVPN (ovpn1198) |
| +-- IKEv2 (strongSwan) |
| |
| Network C (10.100.2.0/24) |
| +-- ... |
+--------------------------------------+
- Networks define subnets, upstream routing, bandwidth limits, and protocol settings
- Clients belong to a network and inherit its configuration
- Upstreams allow routing network traffic through external WireGuard VPN servers
Upstream Tunnels
Route client traffic through external WireGuard VPN servers for:
- Geographic IP rotation — clients appear from different countries
- Multi-hop privacy — add an extra encryption layer
- ISP bypass — route traffic through a clean IP when your server IP is blocked
- Dedicated exit nodes — separate business and personal traffic
Per-Network Control
Each network operates independently with its own:
- Subnet (IPv4 and IPv6)
- VPN protocol settings and ports
- Bandwidth limits (download/upload per network and per client)
- Firewall rules (filter, NAT, DNAT, mangle)
- Traffic control classes
- Upstream (direct internet or WireGuard tunnel)
- Custom routes pushed to clients
- Port forwarding rules
Security & Access Control
- Role-based access — permission groups with 36+ granular permissions
- Multi-user — multiple administrators with different access levels
- API tokens — create tokens with IP restrictions and expiration dates
- Session security — IP-pinned sessions, login lockout protection
- Automatic firewall — per-network isolation via ipset, per-client mangle rules
Operations
- Traffic monitoring — per-client and per-network traffic statistics with daily breakdown
- Real-time bandwidth — live traffic control with drops, overlimits, throughput
- InfluxDB + Grafana — export metrics for advanced dashboards
- Backups — automatic daily/hourly backups with FTP upload support
- One-time links — generate self-service configuration links for end users
- REST API — 170+ endpoints with full OpenAPI 3.0 documentation
Navigation
The web interface is organized into dropdown menus:
| Networks | Clients | VPN Servers | Settings |
- Networks — list, add networks, and manage peering
- Clients — list, add clients, and view online connections
- VPN Servers — configure WireGuard, AmneziaWG, OpenVPN, IKEv2, and Upstreams
- Settings — networking, system, environment, firewall, DNS, monitoring, backups, OTL, users, permissions, API tokens, license
Technical Specifications
| Component | Details |
|---|---|
| OS | Debian 12/13, Ubuntu 22.04+ |
| Protocols | WireGuard, AmneziaWG, OpenVPN 2.6+, IKEv2 (strongSwan 6.x) |
| Web Interface | HTTPS with Let's Encrypt auto-SSL |
| API | REST API, 170+ endpoints, OpenAPI 3.0 |
| DNS | Built-in bind9 DNS server |
| Firewall | iptables/ip6tables with ipset |
| Monitoring | rsyslog + telegraf + InfluxDB |
| Themes | Light / Dark / Auto (system) |
| Max Clients | 16,383 per server (across all networks) |
| Binary | Single ~34MB Go binary, no runtime dependencies |
Architecture Overview
+-----------------------------------------------------------------+
| Web Interface |
| (Bootstrap 5, jQuery, AJAX) |
+-----------------------------------------------------------------+
| REST API (Gin) |
| 170+ endpoints, OpenAPI |
+-----------------------------------------------------------------+
| Core Engine (Go) |
| +----------+ +-----------+ +---------+ +---------+ +---------+ |
| |WireGuard | | AmneziaWG | | OpenVPN | | IKEv2 | |Firewall | |
| | (wg) | | (awg) | |(openvpn)| |(strgSwn)| |(iptables)|
| +----------+ +-----------+ +---------+ +---------+ +---------+ |
| +----------+ +-----------+ +---------+ +---------+ +---------+ |
| |Upstreams | | DNS | | TC | |Monitoring| | OTL | |
| | (wgupN) | | (bind9) | | (tc) | |(telegraf)| |(tokens)| |
| +----------+ +-----------+ +---------+ +---------+ +---------+ |
+-----------------------------------------------------------------+
| Linux Kernel |
| WireGuard / AmneziaWG module, Netfilter, TC, iproute2 |
+-----------------------------------------------------------------+
WHMCS Billing & Provisioning Automation
Selling VPN services or hosting packages? PUQ Software provides an official provisioning module for WHMCS:
PUQVPNCP WHMCS Provisioning Module
Key Capabilities:
- Instant Automated Provisioning: Automatically provisions client VPN accounts upon invoice payment.
- Lifecycle Management: Automated suspension on overdue invoices, unsuspension on payment, and termination on cancellation.
- Bandwidth Shaping & Traffic Quotas: Synchronizes download/upload speed limits and traffic transfer limits directly from WHMCS product settings.
- Client Area Self-Service: Customers can view credentials, download WireGuard and OpenVPN configurations, generate obfuscated AmneziaWG profiles, and scan QR codes right from their WHMCS client portal.
- Multi-Server & Multi-Network: Route client accounts to specific PUQVPNCP servers and networks based on WHMCS product configuration.
License
PUQVPNCP requires an active license. Licenses can be purchased at:
https://puqcloud.com/store/puqvpncp
The license defines the maximum number of VPN clients and is validated periodically through the PUQ Cloud license server.