# VPN Protocols Supported by Amnezia Client: WireGuard, OpenVPN, IKEv2, AWG, and Xray

> Discover the VPN protocols Amnezia Client supports: WireGuard, OpenVPN, IKEv2, AWG, and Xray. Learn about their implementation in the Amnezia VPN repository.

- Repository: [Amnezia VPN/amnezia-client](https://github.com/amnezia-vpn/amnezia-client)
- Tags: deep-dive
- Published: 2026-07-29

---

**The Amnezia VPN client supports five core tunneling protocols—WireGuard, OpenVPN, IKEv2, AWG (Amnezia WireGuard), and Xray (V2Ray-based)—each implemented with dedicated C++ configurators, Qt UI models, and protocol-specific constants in the `amnezia-vpn/amnezia-client` repository.**

The `amnezia-client` codebase organizes VPN protocols under a unified abstraction layer defined in [`client/core/utils/protocolEnum.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/utils/protocolEnum.h), while concrete implementations reside in separate `protocols::` namespaces and platform-specific daemon utilities. This architecture allows the Qt-based application to dynamically instantiate the correct configurator and installer based on user selection.

## Core Protocol Architecture

At the heart of the protocol system lies the `Proto` enum defined in [`client/core/utils/protocolEnum.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/utils/protocolEnum.h), which enumerates every supported tunnel type. Each protocol exposes its default parameters—ports, MTU values, and cryptographic settings—through a dedicated namespace (e.g., `protocols::wireguard::defaultPort`).

The UI layer binds to these implementations via model classes in `client/ui/models/protocols/`, while the daemon layer handles low-level tunnel management through utilities like [`wireguardutilslinux.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/wireguardutilslinux.cpp) and platform-specific configurators.

## WireGuard (Native Implementation)

**WireGuard** is implemented as a first-class native tunnel across Linux, macOS, and Windows, bypassing external binary dependencies where possible.

Key implementation files include:

- **[`client/core/configurators/wireguardConfigurator.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/configurators/wireguardConfigurator.h)** – Defines the `WireGuardConfigurator` class responsible for generating WireGuard `.conf` structures and managing interface parameters.
- **[`client/ui/models/protocols/wireguardConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/ui/models/protocols/wireguardConfigModel.cpp)** – Provides the Qt model backing the QML UI for WireGuard settings.
- **[`client/platforms/linux/daemon/wireguardutilslinux.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/platforms/linux/daemon/wireguardutilslinux.cpp)** – Contains platform-specific WireGuard utility wrappers for Linux daemon control.

The protocol defaults are accessed via the `protocols::wireguard` namespace constants, ensuring consistent port and MTU assignments across the application.

## OpenVPN (Classic Binary-Based)

**OpenVPN** support leverages the official `openvpn` binary, with Amnezia acting as a sophisticated configuration manager and process wrapper.

Implementation centers on:

- **[`client/core/configurators/openVpnConfigurator.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/configurators/openVpnConfigurator.h)** – Implements `OpenVpnConfigurator`, handling cipher selection, certificate embedding, and route configuration.
- **[`client/ui/models/protocols/openvpnConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/ui/models/protocols/openvpnConfigModel.cpp)** – Supplies the UI model for OpenVPN-specific options such as protocol (UDP/TCP) and port selection.

This configurator integrates with the `protocols::openvpn` constants for default cipher suites and listening ports.

## IKEv2 (strongSwan Integration)

**IKEv2** connectivity is provided through integration with the strongSwan IPsec stack, offering enterprise-grade security with certificate-based authentication.

Source files include:

- **[`client/core/configurators/ikev2Configurator.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/configurators/ikev2Configurator.h)** – Manages IKEv2 profile generation, CA certificate handling, and connection parameter negotiation.
- **[`client/ui/models/protocols/ikev2ConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/ui/models/protocols/ikev2ConfigModel.cpp)** – Exposes IKEv2 configuration options to the Qt Quick interface.

The implementation relies on `protocols::ikev2` defaults for cryptographic proposals and rekeying intervals.

## AWG (Amnezia WireGuard)

**AWG** represents a specialized WireGuard variant that applies Amnezia-specific optimizations and defaults—such as custom MTU values and port configurations—while maintaining full WireGuard compatibility.

The implementation resides primarily in:

- **[`client/ui/models/protocols/awgConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/ui/models/protocols/awgConfigModel.cpp)** – Extends the base WireGuard model with AWG-specific parameters, inheriting from the standard WireGuard utilities while overriding default values from the `protocols::awg` namespace.

## Xray (V2Ray-Based Proxy Protocols)

**Xray** support enables modern proxy protocols including VMess, VLess, Trojan, and Shadowsocks through the Xray core. This provides obfuscation capabilities and traffic masking beyond traditional VPN tunnels.

Key files:

- **[`client/core/configurators/xrayConfigurator.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/configurators/xrayConfigurator.h)** – Orchestrates Xray JSON configuration generation, routing rules, and transport layer security settings.
- **[`client/ui/models/protocols/xrayConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/ui/models/protocols/xrayConfigModel.cpp)** – Binds Xray-specific outbound and inbound settings to the user interface.

Configuration defaults are managed through the `protocols::xray` namespace, covering transport protocols (WebSocket, gRPC, TCP) and security layers.

## Working with Protocol Configurators in Code

The Amnezia client uses a polymorphic configurator pattern to switch protocols at runtime. The following examples demonstrate instantiating configurators and applying protocol defaults:

```cpp
// Example: Establishing a WireGuard connection with default port
#include "wireguardConfigurator.h"

WireGuardConfigurator wgConf;
wgConf.setPort(QString::number(protocols::wireguard::defaultPort));
wgConf.setMtu(protocols::wireguard::defaultMtu);

// Apply to connection manager
Amnezia::Client::VpnConnection conn;
conn.applyConfigurator(&wgConf);
conn.start();

```

```cpp
// Example: Switching to OpenVPN with namespace constants
#include "openVpnConfigurator.h"

OpenVpnConfigurator ovpnConf;
ovpnConf.setPort(protocols::openvpn::defaultPort);
ovpnConf.setCipher(protocols::openvpn::defaultCipher);
ovpnConf.setProtocol(protocols::openvpn::defaultProto);

conn.applyConfigurator(&ovpnConf);
conn.restart();

```

```cpp
// Example: Xray configuration for VMess outbound
#include "xrayConfigModel.h"
#include "xrayConfigurator.h"

XrayConfigurator xrayConf;
xrayConf.setOutboundProtocol("vmess");
xrayConf.setServerPort(protocols::xray::defaultPort);
xrayConf.applyTransportSettings("ws"); // WebSocket transport

```

## Protocol Constants and Defaults

All supported protocols expose their default runtime parameters through strongly-typed namespaces under `protocols::`. These constants ensure cross-platform consistency and simplify configuration validation:

- **`protocols::wireguard::defaultPort`** – WireGuard listening port (typically 51820).
- **`protocols::wireguard::defaultMtu`** – Tunnel MTU optimized for WireGuard encapsulation.
- **`protocols::openvpn::defaultCipher`** – Default OpenVPN encryption cipher (e.g., AES-256-GCM).
- **`protocols::ikev2::defaultPort`** – Standard IKEv2 UDP port (500/4500).
- **`protocols::xray::defaultPort`** – Xray inbound listening port.

These values are referenced throughout [`protocolsModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/protocolsModel.cpp) when initializing new connections and validating user input against known-safe defaults.

## Summary

- **Five protocols supported**: WireGuard, OpenVPN, IKEv2, AWG, and Xray (V2Ray-based).
- **Modular architecture**: Each protocol implements a dedicated configurator class (e.g., `WireGuardConfigurator`, `XrayConfigurator`) and Qt model (e.g., [`wireguardConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/wireguardConfigModel.cpp)).
- **Namespace organization**: Protocol defaults are centralized in `protocols::` namespaces (e.g., `protocols::wireguard::defaultPort`) defined alongside the `Proto` enum in [`client/core/utils/protocolEnum.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/utils/protocolEnum.h).
- **Platform abstraction**: Native protocols like WireGuard use daemon utilities (e.g., [`wireguardutilslinux.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/wireguardutilslinux.cpp)), while OpenVPN orchestrates external binaries.
- **Dynamic switching**: The client applies configurators polymorphically at runtime via `VpnConnection::applyConfigurator()`, enabling seamless protocol changes without restart.

## Frequently Asked Questions

### How do I programmatically detect which protocols are available in Amnezia Client?

The `Proto` enum in [`client/core/utils/protocolEnum.h`](https://github.com/amnezia-vpn/amnezia-client/blob/main/client/core/utils/protocolEnum.h) defines all compiled protocol identifiers. Check the [`protocolsModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/protocolsModel.cpp) implementation to see how the UI queries protocol availability based on platform capabilities and installed binaries (e.g., checking for `openvpn` binary presence for OpenVPN support).

### What is the difference between WireGuard and AWG in Amnezia Client?

**AWG (Amnezia WireGuard)** is essentially WireGuard with Amnezia-specific default configurations—custom MTU values, predefined ports, and optimized keepalive intervals—implemented in [`awgConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/awgConfigModel.cpp). Unlike standard WireGuard defined in [`wireguardConfigModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/wireguardConfigModel.cpp), AWG injects these optimized defaults automatically while using the same underlying kernel implementation and [`wireguardutilslinux.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/wireguardutilslinux.cpp) daemon utilities.

### Can I use multiple VPN protocols simultaneously with Amnezia Client?

The current architecture in `amnezia-vpn/amnezia-client` supports one active tunnel per `VpnConnection` instance. While the UI in [`protocolsModel.cpp`](https://github.com/amnezia-vpn/amnezia-client/blob/main/protocolsModel.cpp) allows rapid switching between protocols by swapping configurators (e.g., from `WireGuardConfigurator` to `XrayConfigurator`), true simultaneous multi-protocol connectivity would require multiple daemon instances and is not implemented in the current codebase.

### Where are the default port numbers defined for each protocol?

Default ports are defined as `constexpr` values within their respective `protocols::` namespaces. For example, `protocols::wireguard::defaultPort` is declared in the WireGuard protocol header, while `protocols::xray::defaultPort` handles Xray defaults. These constants are consumed by UI models in `client/ui/models/protocols/` and configurators in `client/core/configurators/` to pre-populate connection settings.