# 01. Description

## Overview

**PUQVPNCP** is a comprehensive VPN server management panel that supports four VPN protocols simultaneously: **WireGuard**, **AmneziaWG**, **OpenVPN**, and **IKEv2/IPsec**. It provides a modern web interface for managing VPN networks, clients, firewall rules, traffic control, and monitoring — all from a single dashboard.

The panel is designed for VPN service providers, hosting companies, and system administrators who need to manage hundreds or thousands of VPN clients across multiple networks with fine-grained control over bandwidth, routing, and anti-censorship security.

---

## Key Features

### Multi-Protocol Support

PUQVPNCP is unique in supporting **four VPN protocols at once** on the same server:

| Protocol | Technology | Best For |
|----------|-----------|----------|
| **WireGuard** | Modern kernel-level VPN | Speed, low latency, mobile devices |
| **AmneziaWG** | Obfuscated WireGuard fork | Evading Deep Packet Inspection (DPI), strict censorship, ISP blocking |
| **OpenVPN** | Battle-tested SSL/TLS VPN | Compatibility, restrictive networks |
| **IKEv2/IPsec** | Native OS support (strongSwan) | iOS, macOS, Windows — native connection, no app required |

Each client can connect via **any** enabled protocol using the **same IP address**. The panel automatically generates configuration files, QR codes, and certificates for each protocol.

### Network Architecture

```
                   +--------------------------------------+
                   |          PUQVPNCP Server             |
                   |                                      |
Internet <---------|  Network A (10.0.0.0/24)             |
                   |    |-- WireGuard  (wg51820)          |
                   |    |-- AmneziaWG  (awg51821)         |
                   |    |-- OpenVPN    (ovpn1197)         |
                   |    +-- IKEv2      (strongSwan)       |
                   |                                      |
Upstream VPN <-----|  Network B (10.100.1.0/24)           |
(wgup0)            |    |-- WireGuard  (wg51822)          |
                   |    |-- AmneziaWG  (awg51823)         |
                   |    |-- OpenVPN    (ovpn1198)         |
                   |    +-- IKEv2      (strongSwan)       |
                   |                                      |
                   |  Network C (10.100.2.0/24)           |
                   |    +-- ...                           |
                   +--------------------------------------+
```

- **Networks** define subnets, upstream routing, bandwidth limits, and protocol settings
- **Clients** belong to a network and inherit its configuration
- **Upstreams** allow routing network traffic through external WireGuard VPN servers

### Upstream Tunnels

Route client traffic through external WireGuard VPN servers for:

- **Geographic IP rotation** — clients appear from different countries
- **Multi-hop privacy** — add an extra encryption layer
- **ISP bypass** — route traffic through a clean IP when your server IP is blocked
- **Dedicated exit nodes** — separate business and personal traffic

### Per-Network Control

Each network operates independently with its own:

- Subnet (IPv4 and IPv6)
- VPN protocol settings and ports
- Bandwidth limits (download/upload per network and per client)
- Firewall rules (filter, NAT, DNAT, mangle)
- Traffic control classes
- Upstream (direct internet or WireGuard tunnel)
- Custom routes pushed to clients
- Port forwarding rules

### Security & Access Control

- **Role-based access** — permission groups with 36+ granular permissions
- **Multi-user** — multiple administrators with different access levels
- **API tokens** — create tokens with IP restrictions and expiration dates
- **Session security** — IP-pinned sessions, login lockout protection
- **Automatic firewall** — per-network isolation via ipset, per-client mangle rules

### Operations

- **Traffic monitoring** — per-client and per-network traffic statistics with daily breakdown
- **Real-time bandwidth** — live traffic control with drops, overlimits, throughput
- **InfluxDB + Grafana** — export metrics for advanced dashboards
- **Backups** — automatic daily/hourly backups with FTP upload support
- **One-time links** — generate self-service configuration links for end users
- **REST API** — 170+ endpoints with full OpenAPI 3.0 documentation

---

## Navigation

The web interface is organized into dropdown menus:

| | | | |
|---|---|---|---|
| ![Networks menu](https://doc.puq.info/uploads/images/gallery/2026-09/embedded-image-pvvdjoqf.png) | ![Clients menu](https://doc.puq.info/uploads/images/gallery/2026-09/embedded-image-qrgo2t7q.png) | ![VPN Servers menu](https://doc.puq.info/uploads/images/gallery/2026-09/embedded-image-ovwptpgv.png) | ![Settings menu](https://doc.puq.info/uploads/images/gallery/2026-09/embedded-image-1do9xgy9.png) |
| *Networks* | *Clients* | *VPN Servers* | *Settings* |

- **Networks** — list, add networks, and manage peering
- **Clients** — list, add clients, and view online connections
- **VPN Servers** — configure WireGuard, AmneziaWG, OpenVPN, IKEv2, and Upstreams
- **Settings** — networking, system, environment, firewall, DNS, monitoring, backups, OTL, users, permissions, API tokens, license

---

## Technical Specifications

| Component | Details |
|-----------|---------|
| **OS** | Debian 12/13, Ubuntu 22.04+ |
| **Protocols** | WireGuard, AmneziaWG, OpenVPN 2.6+, IKEv2 (strongSwan 6.x) |
| **Web Interface** | HTTPS with Let's Encrypt auto-SSL |
| **API** | REST API, 170+ endpoints, OpenAPI 3.0 |
| **DNS** | Built-in bind9 DNS server |
| **Firewall** | iptables/ip6tables with ipset |
| **Monitoring** | rsyslog + telegraf + InfluxDB |
| **Themes** | Light / Dark / Auto (system) |
| **Max Clients** | 16,383 per server (across all networks) |
| **Binary** | Single ~34MB Go binary, no runtime dependencies |

---

## Architecture Overview

```
+-----------------------------------------------------------------+
|                        Web Interface                            |
|                  (Bootstrap 5, jQuery, AJAX)                    |
+-----------------------------------------------------------------+
|                        REST API (Gin)                           |
|                   170+ endpoints, OpenAPI                       |
+-----------------------------------------------------------------+
|                       Core Engine (Go)                          |
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
|  |WireGuard | | AmneziaWG | | OpenVPN | | IKEv2   | |Firewall | |
|  |  (wg)    | |   (awg)   | |(openvpn)| |(strgSwn)| |(iptables)|
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
|  |Upstreams | |    DNS    | |   TC    | |Monitoring| |   OTL  | |
|  | (wgupN)  | |  (bind9)  | |  (tc)   | |(telegraf)| |(tokens)| |
|  +----------+ +-----------+ +---------+ +---------+ +---------+ |
+-----------------------------------------------------------------+
|                      Linux Kernel                               |
|   WireGuard / AmneziaWG module, Netfilter, TC, iproute2         |
+-----------------------------------------------------------------+
```

---

## WHMCS Billing & Provisioning Automation

Selling VPN services or hosting packages? PUQ Software provides an official provisioning module for WHMCS:

**[PUQVPNCP WHMCS Provisioning Module](https://puqcloud.com/whmcs-module-puqvpncp.php)**

### Key Capabilities:
- **Instant Automated Provisioning**: Automatically provisions client VPN accounts upon invoice payment.
- **Lifecycle Management**: Automated suspension on overdue invoices, unsuspension on payment, and termination on cancellation.
- **Bandwidth Shaping & Traffic Quotas**: Synchronizes download/upload speed limits and traffic transfer limits directly from WHMCS product settings.
- **Client Area Self-Service**: Customers can view credentials, download WireGuard and OpenVPN configurations, generate obfuscated AmneziaWG profiles, and scan QR codes right from their WHMCS client portal.
- **Multi-Server & Multi-Network**: Route client accounts to specific PUQVPNCP servers and networks based on WHMCS product configuration.

---

## License

PUQVPNCP requires an active license. Licenses can be purchased at:

**[https://puqcloud.com/store/puqvpncp](https://puqcloud.com/store/puqvpncp)**

The license defines the maximum number of VPN clients and is validated periodically through the PUQ Cloud license server.

---


<!-- sync:9e3d8611fa4f42e0 -->