VPN Protocols Supported by Amnezia Client: WireGuard, OpenVPN, IKEv2, AWG, and Xray

The Amnezia VPN client supports five core tunneling protocols—WireGuard, OpenVPN, IKEv2, AWG (Amnezia WireGuard), and Xray (V2Ray-based)—each implemented with dedicated C++ configurators, Qt UI models, and protocol-specific constants in the amnezia-vpn/amnezia-client repository.

The amnezia-client codebase organizes VPN protocols under a unified abstraction layer defined in client/core/utils/protocolEnum.h, while concrete implementations reside in separate protocols:: namespaces and platform-specific daemon utilities. This architecture allows the Qt-based application to dynamically instantiate the correct configurator and installer based on user selection.

Core Protocol Architecture

At the heart of the protocol system lies the Proto enum defined in client/core/utils/protocolEnum.h, which enumerates every supported tunnel type. Each protocol exposes its default parameters—ports, MTU values, and cryptographic settings—through a dedicated namespace (e.g., protocols::wireguard::defaultPort).

The UI layer binds to these implementations via model classes in client/ui/models/protocols/, while the daemon layer handles low-level tunnel management through utilities like wireguardutilslinux.cpp and platform-specific configurators.

WireGuard (Native Implementation)

WireGuard is implemented as a first-class native tunnel across Linux, macOS, and Windows, bypassing external binary dependencies where possible.

Key implementation files include:

The protocol defaults are accessed via the protocols::wireguard namespace constants, ensuring consistent port and MTU assignments across the application.

OpenVPN (Classic Binary-Based)

OpenVPN support leverages the official openvpn binary, with Amnezia acting as a sophisticated configuration manager and process wrapper.

Implementation centers on:

This configurator integrates with the protocols::openvpn constants for default cipher suites and listening ports.

IKEv2 (strongSwan Integration)

IKEv2 connectivity is provided through integration with the strongSwan IPsec stack, offering enterprise-grade security with certificate-based authentication.

Source files include:

The implementation relies on protocols::ikev2 defaults for cryptographic proposals and rekeying intervals.

AWG (Amnezia WireGuard)

AWG represents a specialized WireGuard variant that applies Amnezia-specific optimizations and defaults—such as custom MTU values and port configurations—while maintaining full WireGuard compatibility.

The implementation resides primarily in:

  • client/ui/models/protocols/awgConfigModel.cpp – Extends the base WireGuard model with AWG-specific parameters, inheriting from the standard WireGuard utilities while overriding default values from the protocols::awg namespace.

Xray (V2Ray-Based Proxy Protocols)

Xray support enables modern proxy protocols including VMess, VLess, Trojan, and Shadowsocks through the Xray core. This provides obfuscation capabilities and traffic masking beyond traditional VPN tunnels.

Key files:

Configuration defaults are managed through the protocols::xray namespace, covering transport protocols (WebSocket, gRPC, TCP) and security layers.

Working with Protocol Configurators in Code

The Amnezia client uses a polymorphic configurator pattern to switch protocols at runtime. The following examples demonstrate instantiating configurators and applying protocol defaults:

// Example: Establishing a WireGuard connection with default port
#include "wireguardConfigurator.h"

WireGuardConfigurator wgConf;
wgConf.setPort(QString::number(protocols::wireguard::defaultPort));
wgConf.setMtu(protocols::wireguard::defaultMtu);

// Apply to connection manager
Amnezia::Client::VpnConnection conn;
conn.applyConfigurator(&wgConf);
conn.start();
// Example: Switching to OpenVPN with namespace constants
#include "openVpnConfigurator.h"

OpenVpnConfigurator ovpnConf;
ovpnConf.setPort(protocols::openvpn::defaultPort);
ovpnConf.setCipher(protocols::openvpn::defaultCipher);
ovpnConf.setProtocol(protocols::openvpn::defaultProto);

conn.applyConfigurator(&ovpnConf);
conn.restart();
// Example: Xray configuration for VMess outbound
#include "xrayConfigModel.h"
#include "xrayConfigurator.h"

XrayConfigurator xrayConf;
xrayConf.setOutboundProtocol("vmess");
xrayConf.setServerPort(protocols::xray::defaultPort);
xrayConf.applyTransportSettings("ws"); // WebSocket transport

Protocol Constants and Defaults

All supported protocols expose their default runtime parameters through strongly-typed namespaces under protocols::. These constants ensure cross-platform consistency and simplify configuration validation:

  • protocols::wireguard::defaultPort – WireGuard listening port (typically 51820).
  • protocols::wireguard::defaultMtu – Tunnel MTU optimized for WireGuard encapsulation.
  • protocols::openvpn::defaultCipher – Default OpenVPN encryption cipher (e.g., AES-256-GCM).
  • protocols::ikev2::defaultPort – Standard IKEv2 UDP port (500/4500).
  • protocols::xray::defaultPort – Xray inbound listening port.

These values are referenced throughout protocolsModel.cpp when initializing new connections and validating user input against known-safe defaults.

Summary

  • Five protocols supported: WireGuard, OpenVPN, IKEv2, AWG, and Xray (V2Ray-based).
  • Modular architecture: Each protocol implements a dedicated configurator class (e.g., WireGuardConfigurator, XrayConfigurator) and Qt model (e.g., wireguardConfigModel.cpp).
  • Namespace organization: Protocol defaults are centralized in protocols:: namespaces (e.g., protocols::wireguard::defaultPort) defined alongside the Proto enum in client/core/utils/protocolEnum.h.
  • Platform abstraction: Native protocols like WireGuard use daemon utilities (e.g., wireguardutilslinux.cpp), while OpenVPN orchestrates external binaries.
  • Dynamic switching: The client applies configurators polymorphically at runtime via VpnConnection::applyConfigurator(), enabling seamless protocol changes without restart.

Frequently Asked Questions

How do I programmatically detect which protocols are available in Amnezia Client?

The Proto enum in client/core/utils/protocolEnum.h defines all compiled protocol identifiers. Check the protocolsModel.cpp implementation to see how the UI queries protocol availability based on platform capabilities and installed binaries (e.g., checking for openvpn binary presence for OpenVPN support).

What is the difference between WireGuard and AWG in Amnezia Client?

AWG (Amnezia WireGuard) is essentially WireGuard with Amnezia-specific default configurations—custom MTU values, predefined ports, and optimized keepalive intervals—implemented in awgConfigModel.cpp. Unlike standard WireGuard defined in wireguardConfigModel.cpp, AWG injects these optimized defaults automatically while using the same underlying kernel implementation and wireguardutilslinux.cpp daemon utilities.

Can I use multiple VPN protocols simultaneously with Amnezia Client?

The current architecture in amnezia-vpn/amnezia-client supports one active tunnel per VpnConnection instance. While the UI in protocolsModel.cpp allows rapid switching between protocols by swapping configurators (e.g., from WireGuardConfigurator to XrayConfigurator), true simultaneous multi-protocol connectivity would require multiple daemon instances and is not implemented in the current codebase.

Where are the default port numbers defined for each protocol?

Default ports are defined as constexpr values within their respective protocols:: namespaces. For example, protocols::wireguard::defaultPort is declared in the WireGuard protocol header, while protocols::xray::defaultPort handles Xray defaults. These constants are consumed by UI models in client/ui/models/protocols/ and configurators in client/core/configurators/ to pre-populate connection settings.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →