PUQ Mautic

22. AmneziaWG (Anti-Censorship)

Overview

AmneziaWG is a specialized fork of WireGuard designed to evade Deep Packet Inspection (DPI) and strict internet censorship systems. While standard WireGuard has easily detectable packet signatures, AmneziaWG obfuscates traffic while retaining WireGuard's speed and performance.

Key Capabilities

Requirement: amneziawg (kernel module or DKMS) and amneziawg-tools packages must be installed on the host. Check via Settings > Environment.

Installation

AmneziaWG requires the kernel module (amneziawg-dkms) and CLI tools (amneziawg-tools). Choose the instructions corresponding to your operating system:

Debian (11 / 12 / 13)

Important for Debian: AmneziaWG is compiled on your server as a kernel module via DKMS. On Debian, DKMS requires kernel headers (linux-headers-$(uname -r)) and build tools (build-essential). Without them, the DKMS build will fail.

Copy and run the complete installation block as root:

# 1. Install build tools, DKMS, and current kernel headers
apt-get update && apt-get install -y build-essential dkms linux-headers-$(uname -r)

# 2. Add the official Amnezia PPA repository keyring and source
mkdir -p /etc/apt/keyrings && curl -fsSL "https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x75C9DD72C799870E310542E24166F2C257290828" | gpg --dearmor --yes -o /etc/apt/keyrings/amnezia.gpg
echo "deb [signed-by=/etc/apt/keyrings/amnezia.gpg] https://ppa.launchpadcontent.net/amnezia/ppa/ubuntu noble main" > /etc/apt/sources.list.d/amnezia.list

# 3. Install the DKMS module and tools
apt-get update && apt-get install -y amneziawg-dkms amneziawg-tools

# 4. Load the kernel module
modprobe amneziawg

Ubuntu (22.04 / 24.04 LTS)

Option 1: Using add-apt-repository (standard):

add-apt-repository -y ppa:amnezia/ppa
apt-get update && apt-get install -y amneziawg-dkms amneziawg-tools
modprobe amneziawg

Option 2: Using GPG keyring (minimal systems):

mkdir -p /etc/apt/keyrings && curl -fsSL "https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x75C9DD72C799870E310542E24166F2C257290828" | gpg --dearmor --yes -o /etc/apt/keyrings/amnezia.gpg
echo "deb [signed-by=/etc/apt/keyrings/amnezia.gpg] https://ppa.launchpadcontent.net/amnezia/ppa/ubuntu noble main" > /etc/apt/sources.list.d/amnezia.list
apt-get update && apt-get install -y amneziawg-dkms amneziawg-tools
modprobe amneziawg

Verification

Verify that the module has been compiled and loaded into the kernel:

# Check DKMS compilation status (should show 'installed')
dkms status

# Check that the kernel module is active
lsmod | grep amneziawg

# Check that the awg CLI utility is available
awg --version

Troubleshooting DKMS Compilation & Kernel Updates

If dkms status shows added or error, or if you upgrade the system kernel:

apt-get install -y build-essential dkms linux-headers-$(uname -r)
dpkg-reconfigure amneziawg-dkms
modprobe amneziawg

Note on DNS / resolvconf: If you run awg-quick manually and receive /usr/bin/awg-quick: resolvconf: command not found, install openresolv:

apt-get install -y openresolv

Navigate to VPN Servers > AmneziaWG to access AmneziaWG management. The page provides 5 tabs: Overview, Networks, Settings, Online, and Client Profiles.


Obfuscation Parameters Explained

Parameter Default Description
H1 Random Header type for handshake initiation packets
H2 Random Header type for handshake response packets
H3 Random Header type for cookie reply packets
H4 Random Header type for data transport packets
Jc 4 Number of junk packets injected before handshake (1–128)
Jmin 40 Minimum byte size of junk packets
Jmax 70 Maximum byte size of junk packets
S1 15 Initiation packet junk size in bytes
S2 20 Response packet junk size in bytes

Each network can inherit the global defaults or define custom obfuscation values to match specific ISP bypass requirements.


Overview Tab

AmneziaWG Overview

The Overview tab displays:

Card Description
Service Status Installed amneziawg kernel module and amneziawg-tools package versions
Summary Total number of AmneziaWG networks and clients configured
Online Connections Real-time count of connected AmneziaWG peers with live bandwidth stats

Networks Tab

AmneziaWG Networks

Lists all networks that have AmneziaWG enabled:

Column Description
Name Network name (link to network edit page)
Clients Number of AmneziaWG clients in this network
Interface Interface name (e.g., awg51821)
Network Subnet assigned to this network
Endpoint Server IP and UDP port for AmneziaWG client connections
Bandwidth Upload / download bandwidth limits

Settings Tab

AmneziaWG Settings

Global defaults for AmneziaWG client profiles:


Online Peers Tab

AmneziaWG Online Peers

Shows real-time connected peers with active session data:


Client Profiles Tab

AmneziaWG Client Profiles

Lists all configured AmneziaWG client profiles across networks, indicating network membership, activation status, and cryptographic key status.


Network Configuration

Network Edit — AmneziaWG

When configuring AmneziaWG inside a network:


Client Configuration & QR Codes

Client Edit — AmneziaWG

In the client management page, enabling AmneziaWG automatically generates:

  1. Standard cryptographic keys adapted for AmneziaWG
  2. Obfuscation parameters embedded into client .conf
  3. QR code for instant mobile setup via AmneziaWG apps on iOS and Android

OTL AmneziaWG Configuration

Administrators can configure the AmneziaWG download page on One-Time Links, setting custom button labels and download links for all supported platforms (Android, iOS, Windows, macOS).

OTL AmneziaWG Client View

The end-user sees a clean, self-service page with QR code, configuration preview, config file download button, and direct app store links to the official AmneziaWG clients.


Revision #6
Created 28 September 2026 17:06:20 by Ruslan
Updated 28 September 2026 18:58:45 by Ruslan