VPN Protocols Supported by Amnezia Client: WireGuard, OpenVPN, IKEv2, AWG, and Xray
The Amnezia VPN client supports five core tunneling protocols—WireGuard, OpenVPN, IKEv2, AWG (Amnezia WireGuard), and Xray (V2Ray-based)—each implemented with dedicated C++ configurators, Qt UI models, and protocol-specific constants in the amnezia-vpn/amnezia-client repository.
The amnezia-client codebase organizes VPN protocols under a unified abstraction layer defined in client/core/utils/protocolEnum.h, while concrete implementations reside in separate protocols:: namespaces and platform-specific daemon utilities. This architecture allows the Qt-based application to dynamically instantiate the correct configurator and installer based on user selection.
Core Protocol Architecture
At the heart of the protocol system lies the Proto enum defined in client/core/utils/protocolEnum.h, which enumerates every supported tunnel type. Each protocol exposes its default parameters—ports, MTU values, and cryptographic settings—through a dedicated namespace (e.g., protocols::wireguard::defaultPort).
The UI layer binds to these implementations via model classes in client/ui/models/protocols/, while the daemon layer handles low-level tunnel management through utilities like wireguardutilslinux.cpp and platform-specific configurators.
WireGuard (Native Implementation)
WireGuard is implemented as a first-class native tunnel across Linux, macOS, and Windows, bypassing external binary dependencies where possible.
Key implementation files include:
client/core/configurators/wireguardConfigurator.h– Defines theWireGuardConfiguratorclass responsible for generating WireGuard.confstructures and managing interface parameters.client/ui/models/protocols/wireguardConfigModel.cpp– Provides the Qt model backing the QML UI for WireGuard settings.client/platforms/linux/daemon/wireguardutilslinux.cpp– Contains platform-specific WireGuard utility wrappers for Linux daemon control.
The protocol defaults are accessed via the protocols::wireguard namespace constants, ensuring consistent port and MTU assignments across the application.
OpenVPN (Classic Binary-Based)
OpenVPN support leverages the official openvpn binary, with Amnezia acting as a sophisticated configuration manager and process wrapper.
Implementation centers on:
client/core/configurators/openVpnConfigurator.h– ImplementsOpenVpnConfigurator, handling cipher selection, certificate embedding, and route configuration.client/ui/models/protocols/openvpnConfigModel.cpp– Supplies the UI model for OpenVPN-specific options such as protocol (UDP/TCP) and port selection.
This configurator integrates with the protocols::openvpn constants for default cipher suites and listening ports.
IKEv2 (strongSwan Integration)
IKEv2 connectivity is provided through integration with the strongSwan IPsec stack, offering enterprise-grade security with certificate-based authentication.
Source files include:
client/core/configurators/ikev2Configurator.h– Manages IKEv2 profile generation, CA certificate handling, and connection parameter negotiation.client/ui/models/protocols/ikev2ConfigModel.cpp– Exposes IKEv2 configuration options to the Qt Quick interface.
The implementation relies on protocols::ikev2 defaults for cryptographic proposals and rekeying intervals.
AWG (Amnezia WireGuard)
AWG represents a specialized WireGuard variant that applies Amnezia-specific optimizations and defaults—such as custom MTU values and port configurations—while maintaining full WireGuard compatibility.
The implementation resides primarily in:
client/ui/models/protocols/awgConfigModel.cpp– Extends the base WireGuard model with AWG-specific parameters, inheriting from the standard WireGuard utilities while overriding default values from theprotocols::awgnamespace.
Xray (V2Ray-Based Proxy Protocols)
Xray support enables modern proxy protocols including VMess, VLess, Trojan, and Shadowsocks through the Xray core. This provides obfuscation capabilities and traffic masking beyond traditional VPN tunnels.
Key files:
client/core/configurators/xrayConfigurator.h– Orchestrates Xray JSON configuration generation, routing rules, and transport layer security settings.client/ui/models/protocols/xrayConfigModel.cpp– Binds Xray-specific outbound and inbound settings to the user interface.
Configuration defaults are managed through the protocols::xray namespace, covering transport protocols (WebSocket, gRPC, TCP) and security layers.
Working with Protocol Configurators in Code
The Amnezia client uses a polymorphic configurator pattern to switch protocols at runtime. The following examples demonstrate instantiating configurators and applying protocol defaults:
// Example: Establishing a WireGuard connection with default port
#include "wireguardConfigurator.h"
WireGuardConfigurator wgConf;
wgConf.setPort(QString::number(protocols::wireguard::defaultPort));
wgConf.setMtu(protocols::wireguard::defaultMtu);
// Apply to connection manager
Amnezia::Client::VpnConnection conn;
conn.applyConfigurator(&wgConf);
conn.start();
// Example: Switching to OpenVPN with namespace constants
#include "openVpnConfigurator.h"
OpenVpnConfigurator ovpnConf;
ovpnConf.setPort(protocols::openvpn::defaultPort);
ovpnConf.setCipher(protocols::openvpn::defaultCipher);
ovpnConf.setProtocol(protocols::openvpn::defaultProto);
conn.applyConfigurator(&ovpnConf);
conn.restart();
// Example: Xray configuration for VMess outbound
#include "xrayConfigModel.h"
#include "xrayConfigurator.h"
XrayConfigurator xrayConf;
xrayConf.setOutboundProtocol("vmess");
xrayConf.setServerPort(protocols::xray::defaultPort);
xrayConf.applyTransportSettings("ws"); // WebSocket transport
Protocol Constants and Defaults
All supported protocols expose their default runtime parameters through strongly-typed namespaces under protocols::. These constants ensure cross-platform consistency and simplify configuration validation:
protocols::wireguard::defaultPort– WireGuard listening port (typically 51820).protocols::wireguard::defaultMtu– Tunnel MTU optimized for WireGuard encapsulation.protocols::openvpn::defaultCipher– Default OpenVPN encryption cipher (e.g., AES-256-GCM).protocols::ikev2::defaultPort– Standard IKEv2 UDP port (500/4500).protocols::xray::defaultPort– Xray inbound listening port.
These values are referenced throughout protocolsModel.cpp when initializing new connections and validating user input against known-safe defaults.
Summary
- Five protocols supported: WireGuard, OpenVPN, IKEv2, AWG, and Xray (V2Ray-based).
- Modular architecture: Each protocol implements a dedicated configurator class (e.g.,
WireGuardConfigurator,XrayConfigurator) and Qt model (e.g.,wireguardConfigModel.cpp). - Namespace organization: Protocol defaults are centralized in
protocols::namespaces (e.g.,protocols::wireguard::defaultPort) defined alongside theProtoenum inclient/core/utils/protocolEnum.h. - Platform abstraction: Native protocols like WireGuard use daemon utilities (e.g.,
wireguardutilslinux.cpp), while OpenVPN orchestrates external binaries. - Dynamic switching: The client applies configurators polymorphically at runtime via
VpnConnection::applyConfigurator(), enabling seamless protocol changes without restart.
Frequently Asked Questions
How do I programmatically detect which protocols are available in Amnezia Client?
The Proto enum in client/core/utils/protocolEnum.h defines all compiled protocol identifiers. Check the protocolsModel.cpp implementation to see how the UI queries protocol availability based on platform capabilities and installed binaries (e.g., checking for openvpn binary presence for OpenVPN support).
What is the difference between WireGuard and AWG in Amnezia Client?
AWG (Amnezia WireGuard) is essentially WireGuard with Amnezia-specific default configurations—custom MTU values, predefined ports, and optimized keepalive intervals—implemented in awgConfigModel.cpp. Unlike standard WireGuard defined in wireguardConfigModel.cpp, AWG injects these optimized defaults automatically while using the same underlying kernel implementation and wireguardutilslinux.cpp daemon utilities.
Can I use multiple VPN protocols simultaneously with Amnezia Client?
The current architecture in amnezia-vpn/amnezia-client supports one active tunnel per VpnConnection instance. While the UI in protocolsModel.cpp allows rapid switching between protocols by swapping configurators (e.g., from WireGuardConfigurator to XrayConfigurator), true simultaneous multi-protocol connectivity would require multiple daemon instances and is not implemented in the current codebase.
Where are the default port numbers defined for each protocol?
Default ports are defined as constexpr values within their respective protocols:: namespaces. For example, protocols::wireguard::defaultPort is declared in the WireGuard protocol header, while protocols::xray::defaultPort handles Xray defaults. These constants are consumed by UI models in client/ui/models/protocols/ and configurators in client/core/configurators/ to pre-populate connection settings.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →