21. Diagnostics
Overview
The Diagnostics section provides real-time monitoring, log viewing, and system integrity checking across all VPN protocols, traffic control, monitoring services, and the panel itself.
Diagnostics dropdown menu
| Page | Description |
|---|---|
| WireGuard | WireGuard service status, wg show output, kernel logs |
| AmneziaWG | AmneziaWG service status, awg show output, kernel logs |
| OpenVPN | OpenVPN service status, certificates, instances, connection events, auth log, server logs |
| IKEv2 | strongSwan service status, certificates, ipsec statusall output, IKEv2 logs |
| Traffic Control | Overview of TC classes, per-interface bandwidth statistics with live throughput |
| Telegraf | Telegraf service status, InfluxDB output config, inputs, Telegraf logs |
| System | Server uptime, memory, disk usage, network interfaces, system logs |
| Panel | PUQVPNCP application log viewer (puqvpncp.log) |
| Integrity Check | Full system integrity audit — verifies firewall rules, ipset, routing, TC classes, interfaces |
Permission: All diagnostics pages require the
diagnostics:readpermission. Integrity Check requiresfirewall:read(audit) andfirewall:write(fix).
All log viewers feature:
- Auto-refresh every 3 seconds
- Pause / Resume button to stop auto-refresh
- Line count selector (50, 100, 200, 500 lines)
- Color-coded log entries (errors in red, warnings in yellow, connections in green)
WireGuard
Diagnostics: WireGuard — service status, wg show, kernel logs
Service Status
| Field | Description |
|---|---|
| WireGuard | Installed WireGuard kernel module version |
| WireGuard Tools | Installed wireguard-tools package version |
| Networks | Number of WireGuard-enabled networks |
| Clients | Total number of WireGuard clients |
| Online | Number of currently connected WireGuard peers |
If WireGuard or WireGuard Tools are not installed, or no networks are configured, a warning alert is displayed with instructions.
wg show
Displays the raw output of the wg show command — the standard WireGuard status tool. Shows all active WireGuard interfaces with their public keys, listening ports, and connected peers with handshake times and transfer statistics.
This section is collapsible. Click the header to expand/collapse.
WireGuard Kernel Logs
Displays WireGuard-related kernel messages from journalctl. These logs show low-level WireGuard events such as interface creation, peer handshake failures, and kernel module messages.
AmneziaWG
Diagnostics: AmneziaWG — service status, awg show, and kernel logs
Service Status
| Field | Description |
|---|---|
| AmneziaWG | Installed AmneziaWG kernel module (DKMS) version |
| AmneziaWG Tools | Installed amneziawg-tools package CLI version (awg) |
| Networks | Number of AmneziaWG-enabled networks |
| Clients | Total number of AmneziaWG clients |
| Online | Number of currently connected AmneziaWG peers |
If AmneziaWG or AmneziaWG Tools are not installed, or no networks are configured, an informative warning alert is displayed with repository and package installation instructions for Debian (with build-essential dkms linux-headers-$(uname -r)) and Ubuntu (add-apt-repository -y ppa:amnezia/ppa).
awg show
Displays the raw output of the awg show command — the standard AmneziaWG status tool. Shows all active AmneziaWG interfaces with obfuscation parameters (Jc, Jmin, Jmax, S1, S2, H1, H2, H3, H4), public keys, listening ports, and connected peers with handshake times and transfer statistics.
This section is collapsible. Click the header to expand/collapse.
AmneziaWG Kernel Logs
Displays AmneziaWG-related kernel messages from journalctl. These logs show low-level AmneziaWG events such as interface creation, handshake negotiations, and kernel module messages.
OpenVPN
Service Status and Certificates
Diagnostics: OpenVPN — service status, certificates, instances
The page displays two cards side by side:
Service Status:
| Field | Description |
|---|---|
| OpenVPN | Installed OpenVPN package version |
| easy-rsa | Installed easy-rsa package version |
| Global Status | Whether OpenVPN is globally enabled or disabled |
| Networks | Number of OpenVPN-enabled networks |
| Online | Number of currently connected OpenVPN clients |
Certificates:
| Field | Description |
|---|---|
| CA Certificate | Root CA certificate status (Valid / Not generated / Invalid) |
| Server Certificate | Server TLS certificate status |
| DH Parameters | Diffie-Hellman parameters status |
| TLS Auth Key | HMAC authentication key status |
Instances
Shows a table of all OpenVPN network instances:
| Column | Description |
|---|---|
| Network | Network name (link to network edit page) |
| Port | UDP/TCP port for this instance |
| Status | Running (green) or Stopped (red) |
| PID | Process ID (if running) |
Each OpenVPN-enabled network runs as a separate openvpn process with its own PID file.
Connection Events
Diagnostics: OpenVPN — connection events and authentication log
Displays the OpenVPN connection log (/etc/openvpn/puqvpncp/logs/connections.log). Shows client connect and disconnect events with color coding:
-
Green —
CONNECTevents -
Yellow —
DISCONNECTevents
Authentication Log
Displays the OpenVPN authentication log (/etc/openvpn/puqvpncp/logs/auth.log). Shows authentication attempts with color coding:
-
Green —
AUTH OKevents -
Red —
AUTH FAILEDorAUTH ERRORevents
Server Logs
Diagnostics: OpenVPN — server logs from all network instances
Displays combined server logs from all OpenVPN network instances (/etc/openvpn/puqvpncp/logs/*.log). Each log line is prefixed with the network name in square brackets (e.g., [net1] ...).
IKEv2
Service Status and Certificates
Diagnostics: IKEv2 — service status, certificates, ipsec statusall
The page displays two cards side by side:
Service Status:
| Field | Description |
|---|---|
| strongSwan | Installed strongSwan version |
| Starter PID | PID of the strongSwan starter process |
| Charon PID | PID of the IKE daemon (charon) |
| Global Status | Whether IKEv2 is globally enabled or disabled |
| Server Domain | Domain configured for IKEv2 server certificates |
| Online | Number of currently connected IKEv2 clients |
Certificates:
| Field | Description |
|---|---|
| CA Certificate | Root CA certificate status (Valid / Not generated / Invalid) |
| Server Certificate | Server certificate status |
ipsec statusall
Displays the raw output of the ipsec statusall command — the standard strongSwan status tool. Shows detailed information about:
- IKE charon daemon status (version, uptime, memory, threads, plugins)
- Virtual IP pools with size/online/offline counters
- Active security associations (SAs)
- Connection definitions
This section is collapsible.
IKEv2 / strongSwan Logs
Diagnostics: IKEv2 — strongSwan logs
Displays strongSwan logs from journalctl. Shows IKE negotiation events, connection establishments, certificate validations, and authentication messages. The system tries strongswan unit first, then falls back to charon syslog tag.
Traffic Control
Diagnostics: Traffic Control — overview and per-interface TC classes
Overview
| Field | Description |
|---|---|
| Managed Interfaces | Total number of network interfaces with TC rules |
| Total TC Classes | Total number of HTB traffic control classes across all interfaces |
| Total Bytes Processed | Sum of all bytes processed by TC classes |
| Total Drops | Sum of all dropped packets (highlighted in red if > 0) |
The overview auto-refreshes every 2 seconds.
Per-Interface Tables
Below the overview, each managed interface is displayed as a separate card showing all its TC classes:
| Column | Description |
|---|---|
| Handle | TC class handle (e.g., 1:806e) |
| Type | Class type — root for the root class, or direction + protocol (e.g., DL IPv4 #110, UL IPv6 #119) |
| Rate | Configured bandwidth rate |
| Bytes | Total bytes processed by this class |
| Packets | Total packets processed |
| Drops | Dropped packets (highlighted in red if > 0) |
| Overlimits | Overlimit events (highlighted in yellow if > 0) |
| Throughput | Real-time throughput calculated from byte deltas between refreshes |
Interfaces include:
-
Gateway interfaces (e.g.,
ens18) — main server network interfaces -
WireGuard interfaces (e.g.,
wg51824) — per-network WireGuard tunnel interfaces -
OpenVPN interfaces (e.g.,
ovpn1197) — per-network OpenVPN tunnel interfaces -
Upstream interfaces (e.g.,
wgup1) — upstream WireGuard tunnel interfaces
Telegraf
Diagnostics: Telegraf — service status, InfluxDB config, inputs, logs
Service Info
Three cards are displayed:
Telegraf Service:
| Field | Description |
|---|---|
| Version | Installed Telegraf version |
| Status | Running (with PID) or Stopped |
InfluxDB Output:
| Field | Description |
|---|---|
| Enabled | Whether InfluxDB output is enabled |
| URL | InfluxDB server URL |
| Bucket | InfluxDB bucket name |
| Organization | InfluxDB organization |
Inputs:
| Field | Description |
|---|---|
| Socket Listener | Whether the Unix socket input is active (receives metrics from PUQVPNCP) |
| HTTP Metrics | Whether the HTTP metrics endpoint is active |
Telegraf Logs
Displays Telegraf service logs from journalctl with color coding:
-
Red — Error messages (
E!) -
Yellow — Warning messages (
W!) -
Gray — Debug messages (
D!)
System
Diagnostics: System — uptime, memory, disk usage, interfaces
System Info Cards
Four cards are displayed:
Uptime — output of the uptime command showing server uptime, number of users, and load averages.
Memory — output of free -h showing total, used, free, shared, buffers/cache, and available memory for both RAM and swap.
Disk Usage — output of df -h showing mounted filesystem, size, used space, available space, and usage percentage for the root partition.
Interfaces — output of ip -br addr showing all network interfaces with their status (UP/DOWN) and assigned IP addresses. Includes physical interfaces, WireGuard interfaces, OpenVPN tunnel interfaces, and upstream tunnels.
System Logs (puqvpncp)
Diagnostics: System — PUQVPNCP system logs
Displays PUQVPNCP service logs from journalctl (syslog tag puqvpncp). Shows application events such as API requests, system operations, network changes, and service lifecycle events.
Panel Log
Diagnostics: Panel Log — puqvpncp.log viewer
Displays the PUQVPNCP application log file (puqvpncp.log in the configured LogDir directory, default /var/log/puqvpncp/).
This is the application's own log file (separate from journalctl system logs). Log entries are color-coded by level:
-
Red —
ERROR:messages -
Yellow —
WARN:messages -
Gray —
DEBUG:messages -
Normal —
INFO:messages
The log format is: timestamp LEVEL: message (e.g., 2026-03-11T17:18:00.000Z INFO: ReloadNetworks: setting iptables).
Integrity Check
Integrity Check — summary, log table, and last run info
The Integrity Check performs a comprehensive audit of the entire PUQVPNCP system configuration. It verifies that all firewall rules, routing tables, ipset entries, traffic control classes, and network interfaces are correctly configured and match the expected state.
Running a Check
| Button | Description |
|---|---|
| Audit (magnifying glass) | Run a read-only audit — checks all rules and reports issues without making changes |
| Audit & Fix (wrench) | Run an audit and automatically fix any issues found |
The check runs in the background. Results stream in real-time via Server-Sent Events (SSE), with automatic polling fallback if SSE disconnects.
Summary
The summary card shows counters for each check result:
| Counter | Color | Description |
|---|---|---|
| Total | — | Total number of checks performed |
| OK | Green | Checks that passed |
| Failed | Red | Checks that failed (in audit mode, these need fixing) |
| Fixed | Yellow | Checks that were failed but successfully repaired (fix mode only) |
| Errors | Blue | Checks where the fix was applied but still failing |
| Skipped | Gray | Checks that were skipped (e.g., ipset not installed, mangle overflow) |
A progress bar shows the proportion of each result type.
Filter Buttons
Filter the log table by status:
- All — show all entries
- Failed — show failed, fixed, error, and skipped entries (default)
- Fixed — show only fixed entries
- OK — show only passed entries
- Skipped — show only skipped entries
Log Table
| Column | Description |
|---|---|
| Time | Timestamp of the check |
| Status | Result badge (OK / FAILED / FIXED / ERROR / SKIPPED) |
| Category | Check category (see below) |
| Network | Network and/or client name (if applicable) |
| Description | What was checked |
| Detail | Additional information (e.g., "Fixed", error message) |
Check Categories
The integrity check performs 9 phases, covering all aspects of the system:
| Category | Phase | What is Checked |
|---|---|---|
| System | 1 | IPv4 forwarding enabled, INPUT/FORWARD/OUTPUT chain policies, system_PUQVPNCP rule |
| Global Rules | 2 | Pre-filter rules, peering ACCEPT rules (A→B, B→A), intra-network ACCEPT, isolation DROP (ipset), post-filter rules |
| ipset | 3 | puq_vpn_nets ipset exists, each network subnet is a member |
| Chains | 4 | Per-network chains exist in filter (PQ_), nat SNAT (PQN_), nat DNAT (PQD_), mangle (PQM_) — plus jump rules from built-in chains |
| NAT | 5 | SNAT rules for each network's upstream IP |
| Mangle | 5 | Per-client mangle marks for download (dst) and upload (src) traffic |
| Network Rules | 5 | Route ACCEPT rules for custom routes |
| Policy Routing | 6 | Upstream WG tunnel ip rule / ip route table, WG/OpenVPN fwmark-based policy routing |
| CONNMARK | 7 | WG and OpenVPN CONNMARK rules in PREROUTING (mangle) |
| Traffic Control | 8 | Root HTB qdisc on gateway, VPN, and upstream interfaces; per-client TC classes |
| Interfaces | 9 | WireGuard interfaces are UP, upstream WG tunnel interfaces are UP |
Last Run
The Last Run card shows information about the most recent integrity check:
| Field | Description |
|---|---|
| Mode | audit or fix |
| Started | When the check started |
| Duration | How long the check took |
| Result | Summary of OK, failed, fixed, errors, and skipped counts |