AmneziaWG
Keywords
| Keyword | Definition |
|---|---|
| ð¡ïž AmneziaWG | A fork of WireGuard that randomizes packet headers, sizes, and timing to resist Deep Packet Inspection while keeping the same audited cryptography. It is the protocol that runs on your server. |
| ð AmneziaWG 2.0 | The current major version that uses dynamic header ranges (instead of fixed values), adds data-level padding (S4), and supports Custom Protocol Signature decoy packets for stronger DPI evasion. |
| ð Deep Packet Inspection (DPI) | A network filtering technique used by ISPs and governments to identify and block VPN traffic by analyzing packet headers, sizes, and handshake patterns. AmneziaWG is specifically designed to defeat it. |
| â¡ WireGuard | A fast, modern VPN protocol with a small codebase and kernel-level performance. It is easily fingerprinted by DPI systems due to its fixed packet structure, which is what AmneziaWG was built to fix. |
| ð Self-hosted VPN | A VPN you deploy and manage on your own server (typically a VPS) rather than subscribing to a commercial provider. You control the keys, config, and infrastructure. |
| ð§ DKMS (Dynamic Kernel Module Support) | A Linux framework that automatically recompiles kernel modules when the system kernel is updated. The AmneziaWG installer uses DKMS to build the high-performance kernel module. |
| ð Obfuscation | The practice of disguising VPN traffic to look like ordinary internet traffic. AmneziaWG obfuscates at the transport layer by randomizing headers, adding padding, sending decoy packets, and firing junk packets. |
| ð Split tunneling | A routing configuration where only specific traffic (e.g., blocked sites) goes through the VPN while the rest uses your direct connection. Useful in countries with partial censorship. |
| ð¥ïž KVM vs LXC | KVM is full virtualization with a dedicated kernel, required for loading custom kernel modules like AmneziaWG. LXC is container-based virtualization that shares the host kernel and cannot load custom modules. |
| ðª CPS (Custom Protocol Signature) | An AmneziaWG 2.0 feature that sends decoy packets mimicking other protocols (QUIC, DNS, SIP) before the real handshake, fooling DPI systems into classifying the traffic as normal. |
Self-Host an AmneziaWG VPN Server â Complete Guide

AmneziaWG is a protocol designed to solve a specific problem: how do you get WireGuard’s speed when the networks you’re connecting through actively try to block it? It’s a fork of WireGuard built by the Amnezia VPN team, and it does one thing that the original doesn’t â it randomizes the transport layer so Deep Packet Inspection systems can’t fingerprint it. The encryption underneath stays exactly the same. What changes is how the packets look on the wire.
The broader landscape of VPN obfuscation has been an arms race for years. Tools like Shadowsocks, VLESS+Reality, and OpenVPN with obfs4 all attempt to disguise traffic in different ways â some as proxies, some as full tunnels, some with heavy performance costs. AmneziaWG sits in a specific niche: it’s a full VPN tunnel with WireGuard-level performance and built-in DPI resistance, all in one package. And since it’s open-source, you can self-host it on your own server.
But here’s the problem that makes this necessary. You set up WireGuard. It works perfectly â fast, clean, reliable. Then one day it stops. No error message, no timeout, no connection refused. The packets just vanish. That’s what DPI blocking looks like in practice: your tunnel is still running, your config is still correct, and nothing gets through. This is the reality in Russia (where WireGuard has roughly a 12% success rate), Iran (98% packet loss), and a growing list of countries including China, Egypt, UAE, Turkey, Belarus, Uzbekistan, Kazakhstan, Myanmar, and Pakistan.

Traditional alternatives don’t fully solve this. Shadowsocks is a proxy, not a full VPN tunnel â your DNS and non-TCP traffic still leak. OpenVPN with obfs4 works but carries roughly 25% performance overhead. VLESS+Reality offers strong obfuscation but is proxy-based and complex to configure. AmneziaWG fills the gap: a complete VPN tunnel with WireGuard’s speed and DPI resistance baked in.
This guide walks you through deploying a fully functional AmneziaWG 2.0 server on any KVM VPS in under 15 minutes using a single community installer script. By the end, you’ll have a working VPN tunnel you can connect to from any device. The steps are provider-agnostic â they work on any VPS with root SSH access, whether that’s from AlexHost, AvaHost, or elsewhere. This is written for intermediate tech users who are comfortable with SSH and basic Linux commands.
One clarification before we start: AmneziaWG is the protocol. AmneziaVPN is the client app that connects to it. They’re related but distinct â like TLS is to your browser. You’ll need the app to connect, but the protocol is what runs on your server.
But before we deploy anything, you need to understand what makes AmneziaWG different from WireGuard â and why that difference matters when DPI is watching.
What Is AmneziaWG? (The Mental Model)
WireGuard is elegant by design. It has a small codebase, uses modern cryptography, and runs in the Linux kernel for near-native performance. But that elegance comes with a visibility problem: every WireGuard packet carries the same fixed header structure, the same fixed packet sizes, and the same handshake pattern. To a Deep Packet Inspection system, a WireGuard tunnel has a signature as clear as a barcode. Once a DPI box learns that signature, it can drop every packet without blocking the port or closing the connection.

Think of it this way. WireGuard is like a courier who always wears the same uniform â fast, reliable, and efficient. But anyone watching the road learns to recognize that uniform and can stop the courier at any checkpoint. AmneziaWG is the same courier carrying the same packages, but they change uniforms at every checkpoint. Same person, same cargo, completely different appearance.
The version history matters here. AmneziaWG 1.x introduced custom headers that differed from WireGuard’s fixed values â it helped for a while, but DPI systems adapted. AmneziaWG 2.0, released in late 2025, randomizes everything: headers change per packet, padding varies per message, and decoy packets mimic other protocols before the real handshake begins. There is no universal signature to detect because every AmneziaWG 2.0 server generates its own unique parameter set. Each server speaks its own dialect.
When all obfuscation parameters are set to zero, AmneziaWG behaves identically to WireGuard â it’s fully backward compatible at the protocol level. But with parameters active (which is the default), it becomes something WireGuard cannot be: a fast VPN tunnel that DPI systems struggle to identify.
So how exactly does AmneziaWG scramble its traffic? Let’s look at the four obfuscation layers that make DPI blind â and why they add almost no speed cost.
How AmneziaWG Hides From DPI (Without Losing Speed)
AmneziaWG 2.0 uses four layered obfuscation techniques that work together. Each one targets a different way DPI systems identify VPN traffic. Together, they make every server’s traffic look unique.
Dynamic Headers (H1âH4)
WireGuard uses fixed 32-bit message type identifiers:
- 1 â for initiation
- 2 â for response
- 3 â for cookie reply
- 4 â for data
A DPI box scanning traffic just looks for these values. AmneziaWG 2.0 replaces each fixed value with a random number drawn from a configured range. The initiation header (H1) might be any value between 234567 and 345678. The response header (H2) might be between 3456789 and 4567890. These ranges never overlap â the protocol still needs to distinguish packet types internally â but to an outside observer, there’s no single header value to latch onto. Every packet looks different from the last.
Random Padding (S1âS4)
WireGuard’s initiation packet is always exactly 148 bytes. Its response is always exactly 92 bytes. These fixed sizes are another fingerprint. AmneziaWG adds random padding to each packet type: the initiation becomes 148+S1 bytes, the response becomes 92+S2 bytes, the cookie reply becomes 64+S3 bytes, and every data packet gets S4 bytes of padding. S3 and S4 are new in version 2.0 â and S4 is the most significant addition because it touches every single data packet, making session-wide traffic analysis much harder.
There’s one critical constraint: S1+56 must not equal S2. Since the original size difference between initiation and response is 56 bytes (148â92), if the padding values happened to compensate for exactly that difference, the two padded packets would end up the same size â recreating the fingerprint AmneziaWG is trying to eliminate. The installer’s parameter generator enforces this constraint automatically.
Custom Protocol Signature (I1âI5)
Before the real WireGuard handshake begins, the AmneziaWG client sends up to five decoy packets that mimic other protocols â QUIC, DNS, SIP, or custom byte patterns. The server ignores these packets entirely. It just waits for the real handshake.
- A simple configuration: Sends 128 random bytes <r 128>.
- A sophisticated configuration: Sends bytes that look like a QUIC connection initiation (<b 0xc000000001><r 64><t>), complete with a Unix timestamp.
To a DPI system watching the session start, the first packets look like normal web traffic.
Junk Packets (Jc, Jmin, Jmax)
After the decoy packets, the client fires a configurable number of junk packets â pure noise with random sizes between Jmin and Jmax. These blur the timing and size profile of the session start, making it harder for DPI systems to identify where the real handshake begins.
The Speed Question
There’s a number that’s been circulating online: AmneziaWG has 65% overhead. That figure is real, but it refers to the userspace Go implementation â not the kernel module. The community installer used in this guide builds a DKMS kernel module, and the kernel module adds less than 12% overhead total â closer to 3% in real-world benchmarks. On an uncensored network, you’d see roughly 95 Mbps through WireGuard and 92 Mbps through AmneziaWG 2.0. In a censored network, the comparison is 92 Mbps versus zero.
The following table summarizes the parameters the installer generates automatically:
| Parameter | Generated Range | Example Value |
|---|---|---|
Jc (junk packet count) | 4â8 | 6 |
Jmin (min junk size) | 40â89 | 55 |
Jmax (max junk size) | Jmin+100 to Jmin+500 | 380 |
S1 (init padding) | 15â150 | 72 |
S2 (response padding) | 15â150, S1+56â S2 | 56 |
S3 (cookie padding) | 8â55 | 32 |
S4 (data padding) | 4â27 | 16 |
H1 (init header range) | uint32 non-overlapping | 234567-345678 |
H2 (response header range) | uint32 non-overlapping | 3456789-4567890 |
H3 (cookie header range) | uint32 non-overlapping | 56789012-67890123 |
H4 (data header range) | uint32 non-overlapping | 456789012-567890123 |
I1 (CPS packet) | <r N> format | <r 128> |
You don’t need to set any of these manually. The installer generates cryptographically random, constraint-valid values every time.
Now that you know how the obfuscation works, let’s see how AmneziaWG stacks up against the alternatives you might be considering.
AmneziaWG vs Alternatives â Quick Decision Guide

| WireGuard | AmneziaWG 2.0 | OpenVPN+obfs4 | Shadowsocks | VLESS+Reality | |
|---|---|---|---|---|---|
| DPI resistance | Low | High | Medium | Medium | Very High |
| Speed overhead | ~4% | <12% (~3% real-world) | ~25% | ~8% | ~10% |
| Full VPN tunnel | Yes | Yes | Yes | No (proxy) | No (proxy) |
| Runs in kernel | Yes | Yes (DKMS) | No | No | No |
| Setup complexity | Low | Low (with installer) | High | Medium | High |
| Transport | UDP | UDP | TCP/UDP | TCP | TCP |
The decision rules are straightforward:
- No DPI in your country? Use plain WireGuard. It’s simpler and has a larger ecosystem.
- Need maximum DPI resistance and OK with a proxy? VLESS+Reality is the strongest option for obfuscation, but it’s not a full tunnel.
- Want both speed and a full tunnel with obfuscation? AmneziaWG 2.0 is the only option that delivers WireGuard-grade performance with real DPI resistance in a complete VPN tunnel.
- Already using OpenVPN+obfs4 and it still works? No urgent need to switch, but AmneziaWG will be noticeably faster.
This article focuses on AmneziaWG because it’s the only protocol that gives you a full tunnel, kernel-level performance, and built-in obfuscation â all configured by a single script.
If AmneziaWG is the right choice for your situation, here’s exactly what you need before we start deploying.
What You’ll Need Before Starting
Before running the installer, make sure your environment meets these requirements:
| Requirement | Detail | Why |
|---|---|---|
| OS | Ubuntu 24.04 LTS (clean install). Ubuntu 25.10 is experimental. Debian 12/13 work but may needcurl pre-installed. | The installer is tested and fully supported on Ubuntu 24.04. |
| VPS specs | 1 vCore, 1 GB RAM, 25 GB storage. Any $3â5/month plan works. | The installer needs ~2 GB disk and ~1 GB RAM during the DKMS build. The running VPN uses negligible resources. |
| Virtualization | KVM (not OpenVZ, not LXC). | AmneziaWG loads a kernel module via DKMS. LXC shares the host kernel and cannot load custom modules. |
| SSH access | Root or sudo user with password/key authentication. | The installer must run as root. |
| SSH port | Default 22, or pre-opened in UFW if using a non-standard port. | If SSH isn’t on port 22 and you don’t pre-open it, the installer’s firewall setup will lock you out. |
| Client app | Amnezia VPN >= 4.8.12.7 (all platforms). | AWG 2.0 parameters are not understood by older clients. The standard WireGuard client does not support AWG at all. |
â ïž Warning: LXC containers are not supported. If your VPS uses LXC virtualization, the DKMS kernel module build will fail. You must use KVM or bare-metal. Check with your provider if you’re unsure.
â ïž Warning: If your SSH runs on a non-standard port (anything other than 22), you must open it in UFW before running the installer:
sudo ufw allow YOUR_PORT/tcpReplace
YOUR_PORTwith your actual SSH port. The installer enables UFW with a default-deny policy â if your SSH port isn’t allowed, you’ll be locked out immediately.
ð¡ Tip: Wait 5â10 minutes after creating your VPS before running the installer. Cloud-init and background initialization processes can conflict with the
apt-getcalls the installer makes.
With your VPS ready and prerequisites confirmed, let’s deploy AmneziaWG 2.0 using the community installer script â the fastest and most transparent method.
Keywords
| Keyword | Definition |
|---|---|
| ð¡ïž AmneziaWG | A fork of WireGuard that randomizes packet headers, sizes, and timing to resist Deep Packet Inspection while keeping the same audited cryptography. It is the protocol that runs on your server. |
| ð AmneziaWG 2.0 | The current major version that uses dynamic header ranges (instead of fixed values), adds data-level padding (S4), and supports Custom Protocol Signature decoy packets for stronger DPI evasion. |
| ð Deep Packet Inspection (DPI) | A network filtering technique used by ISPs and governments to identify and block VPN traffic by analyzing packet headers, sizes, and handshake patterns. AmneziaWG is specifically designed to defeat it. |
| â¡ WireGuard | A fast, modern VPN protocol with a small codebase and kernel-level performance. It is easily fingerprinted by DPI systems due to its fixed packet structure, which is what AmneziaWG was built to fix. |
| ð Self-hosted VPN | A VPN you deploy and manage on your own server (typically a VPS) rather than subscribing to a commercial provider. You control the keys, config, and infrastructure. |
| ð§ DKMS (Dynamic Kernel Module Support) | A Linux framework that automatically recompiles kernel modules when the system kernel is updated. The AmneziaWG installer uses DKMS to build the high-performance kernel module. |
| ð Obfuscation | The practice of disguising VPN traffic to look like ordinary internet traffic. AmneziaWG obfuscates at the transport layer by randomizing headers, adding padding, sending decoy packets, and firing junk packets. |
| ð Split tunneling | A routing configuration where only specific traffic (e.g., blocked sites) goes through the VPN while the rest uses your direct connection. Useful in countries with partial censorship. |
| ð¥ïž KVM vs LXC | KVM is full virtualization with a dedicated kernel, required for loading custom kernel modules like AmneziaWG. LXC is container-based virtualization that shares the host kernel and cannot load custom modules. |
| ðª CPS (Custom Protocol Signature) | An AmneziaWG 2.0 feature that sends decoy packets mimicking other protocols (QUIC, DNS, SIP) before the real handshake, fooling DPI systems into classifying the traffic as normal. |
Self-Host an AmneziaWG VPN Server â Complete Guide

AmneziaWG is a protocol designed to solve a specific problem: how do you get WireGuard’s speed when the networks you’re connecting through actively try to block it? It’s a fork of WireGuard built by the Amnezia VPN team, and it does one thing that the original doesn’t â it randomizes the transport layer so Deep Packet Inspection systems can’t fingerprint it. The encryption underneath stays exactly the same. What changes is how the packets look on the wire.
The broader landscape of VPN obfuscation has been an arms race for years. Tools like Shadowsocks, VLESS+Reality, and OpenVPN with obfs4 all attempt to disguise traffic in different ways â some as proxies, some as full tunnels, some with heavy performance costs. AmneziaWG sits in a specific niche: it’s a full VPN tunnel with WireGuard-level performance and built-in DPI resistance, all in one package. And since it’s open-source, you can self-host it on your own server.
But here’s the problem that makes this necessary. You set up WireGuard. It works perfectly â fast, clean, reliable. Then one day it stops. No error message, no timeout, no connection refused. The packets just vanish. That’s what DPI blocking looks like in practice: your tunnel is still running, your config is still correct, and nothing gets through. This is the reality in Russia (where WireGuard has roughly a 12% success rate), Iran (98% packet loss), and a growing list of countries including China, Egypt, UAE, Turkey, Belarus, Uzbekistan, Kazakhstan, Myanmar, and Pakistan.

Traditional alternatives don’t fully solve this. Shadowsocks is a proxy, not a full VPN tunnel â your DNS and non-TCP traffic still leak. OpenVPN with obfs4 works but carries roughly 25% performance overhead. VLESS+Reality offers strong obfuscation but is proxy-based and complex to configure. AmneziaWG fills the gap: a complete VPN tunnel with WireGuard’s speed and DPI resistance baked in.
This guide walks you through deploying a fully functional AmneziaWG 2.0 server on any KVM VPS in under 15 minutes using a single community installer script. By the end, you’ll have a working VPN tunnel you can connect to from any device. The steps are provider-agnostic â they work on any VPS with root SSH access, whether that’s from AlexHost, AvaHost, or elsewhere. This is written for intermediate tech users who are comfortable with SSH and basic Linux commands.
One clarification before we start: AmneziaWG is the protocol. AmneziaVPN is the client app that connects to it. They’re related but distinct â like TLS is to your browser. You’ll need the app to connect, but the protocol is what runs on your server.
But before we deploy anything, you need to understand what makes AmneziaWG different from WireGuard â and why that difference matters when DPI is watching.
What Is AmneziaWG? (The Mental Model)
WireGuard is elegant by design. It has a small codebase, uses modern cryptography, and runs in the Linux kernel for near-native performance. But that elegance comes with a visibility problem: every WireGuard packet carries the same fixed header structure, the same fixed packet sizes, and the same handshake pattern. To a Deep Packet Inspection system, a WireGuard tunnel has a signature as clear as a barcode. Once a DPI box learns that signature, it can drop every packet without blocking the port or closing the connection.

Think of it this way. WireGuard is like a courier who always wears the same uniform â fast, reliable, and efficient. But anyone watching the road learns to recognize that uniform and can stop the courier at any checkpoint. AmneziaWG is the same courier carrying the same packages, but they change uniforms at every checkpoint. Same person, same cargo, completely different appearance.
The version history matters here. AmneziaWG 1.x introduced custom headers that differed from WireGuard’s fixed values â it helped for a while, but DPI systems adapted. AmneziaWG 2.0, released in late 2025, randomizes everything: headers change per packet, padding varies per message, and decoy packets mimic other protocols before the real handshake begins. There is no universal signature to detect because every AmneziaWG 2.0 server generates its own unique parameter set. Each server speaks its own dialect.
When all obfuscation parameters are set to zero, AmneziaWG behaves identically to WireGuard â it’s fully backward compatible at the protocol level. But with parameters active (which is the default), it becomes something WireGuard cannot be: a fast VPN tunnel that DPI systems struggle to identify.
So how exactly does AmneziaWG scramble its traffic? Let’s look at the four obfuscation layers that make DPI blind â and why they add almost no speed cost.
How AmneziaWG Hides From DPI (Without Losing Speed)
AmneziaWG 2.0 uses four layered obfuscation techniques that work together. Each one targets a different way DPI systems identify VPN traffic. Together, they make every server’s traffic look unique.
Dynamic Headers (H1âH4)
WireGuard uses fixed 32-bit message type identifiers:
- 1 â for initiation
- 2 â for response
- 3 â for cookie reply
- 4 â for data
A DPI box scanning traffic just looks for these values. AmneziaWG 2.0 replaces each fixed value with a random number drawn from a configured range. The initiation header (H1) might be any value between 234567 and 345678. The response header (H2) might be between 3456789 and 4567890. These ranges never overlap â the protocol still needs to distinguish packet types internally â but to an outside observer, there’s no single header value to latch onto. Every packet looks different from the last.
Random Padding (S1âS4)
WireGuard’s initiation packet is always exactly 148 bytes. Its response is always exactly 92 bytes. These fixed sizes are another fingerprint. AmneziaWG adds random padding to each packet type: the initiation becomes 148+S1 bytes, the response becomes 92+S2 bytes, the cookie reply becomes 64+S3 bytes, and every data packet gets S4 bytes of padding. S3 and S4 are new in version 2.0 â and S4 is the most significant addition because it touches every single data packet, making session-wide traffic analysis much harder.
There’s one critical constraint: S1+56 must not equal S2. Since the original size difference between initiation and response is 56 bytes (148â92), if the padding values happened to compensate for exactly that difference, the two padded packets would end up the same size â recreating the fingerprint AmneziaWG is trying to eliminate. The installer’s parameter generator enforces this constraint automatically.
Custom Protocol Signature (I1âI5)
Before the real WireGuard handshake begins, the AmneziaWG client sends up to five decoy packets that mimic other protocols â QUIC, DNS, SIP, or custom byte patterns. The server ignores these packets entirely. It just waits for the real handshake.
- A simple configuration: Sends 128 random bytes <r 128>.
- A sophisticated configuration: Sends bytes that look like a QUIC connection initiation (<b 0xc000000001><r 64><t>), complete with a Unix timestamp.
To a DPI system watching the session start, the first packets look like normal web traffic.
Junk Packets (Jc, Jmin, Jmax)
After the decoy packets, the client fires a configurable number of junk packets â pure noise with random sizes between Jmin and Jmax. These blur the timing and size profile of the session start, making it harder for DPI systems to identify where the real handshake begins.
The Speed Question
There’s a number that’s been circulating online: AmneziaWG has 65% overhead. That figure is real, but it refers to the userspace Go implementation â not the kernel module. The community installer used in this guide builds a DKMS kernel module, and the kernel module adds less than 12% overhead total â closer to 3% in real-world benchmarks. On an uncensored network, you’d see roughly 95 Mbps through WireGuard and 92 Mbps through AmneziaWG 2.0. In a censored network, the comparison is 92 Mbps versus zero.
The following table summarizes the parameters the installer generates automatically:
| Parameter | Generated Range | Example Value |
|---|---|---|
Jc (junk packet count) | 4â8 | 6 |
Jmin (min junk size) | 40â89 | 55 |
Jmax (max junk size) | Jmin+100 to Jmin+500 | 380 |
S1 (init padding) | 15â150 | 72 |
S2 (response padding) | 15â150, S1+56â S2 | 56 |
S3 (cookie padding) | 8â55 | 32 |
S4 (data padding) | 4â27 | 16 |
H1 (init header range) | uint32 non-overlapping | 234567-345678 |
H2 (response header range) | uint32 non-overlapping | 3456789-4567890 |
H3 (cookie header range) | uint32 non-overlapping | 56789012-67890123 |
H4 (data header range) | uint32 non-overlapping | 456789012-567890123 |
I1 (CPS packet) | <r N> format | <r 128> |
You don’t need to set any of these manually. The installer generates cryptographically random, constraint-valid values every time.
Now that you know how the obfuscation works, let’s see how AmneziaWG stacks up against the alternatives you might be considering.
AmneziaWG vs Alternatives â Quick Decision Guide

| WireGuard | AmneziaWG 2.0 | OpenVPN+obfs4 | Shadowsocks | VLESS+Reality | |
|---|---|---|---|---|---|
| DPI resistance | Low | High | Medium | Medium | Very High |
| Speed overhead | ~4% | <12% (~3% real-world) | ~25% | ~8% | ~10% |
| Full VPN tunnel | Yes | Yes | Yes | No (proxy) | No (proxy) |
| Runs in kernel | Yes | Yes (DKMS) | No | No | No |
| Setup complexity | Low | Low (with installer) | High | Medium | High |
| Transport | UDP | UDP | TCP/UDP | TCP | TCP |
The decision rules are straightforward:
- No DPI in your country? Use plain WireGuard. It’s simpler and has a larger ecosystem.
- Need maximum DPI resistance and OK with a proxy? VLESS+Reality is the strongest option for obfuscation, but it’s not a full tunnel.
- Want both speed and a full tunnel with obfuscation? AmneziaWG 2.0 is the only option that delivers WireGuard-grade performance with real DPI resistance in a complete VPN tunnel.
- Already using OpenVPN+obfs4 and it still works? No urgent need to switch, but AmneziaWG will be noticeably faster.
This article focuses on AmneziaWG because it’s the only protocol that gives you a full tunnel, kernel-level performance, and built-in obfuscation â all configured by a single script.
If AmneziaWG is the right choice for your situation, here’s exactly what you need before we start deploying.
What You’ll Need Before Starting
Before running the installer, make sure your environment meets these requirements:
| Requirement | Detail | Why |
|---|---|---|
| OS | Ubuntu 24.04 LTS (clean install). Ubuntu 25.10 is experimental. Debian 12/13 work but may needcurl pre-installed. | The installer is tested and fully supported on Ubuntu 24.04. |
| VPS specs | 1 vCore, 1 GB RAM, 25 GB storage. Any $3â5/month plan works. | The installer needs ~2 GB disk and ~1 GB RAM during the DKMS build. The running VPN uses negligible resources. |
| Virtualization | KVM (not OpenVZ, not LXC). | AmneziaWG loads a kernel module via DKMS. LXC shares the host kernel and cannot load custom modules. |
| SSH access | Root or sudo user with password/key authentication. | The installer must run as root. |
| SSH port | Default 22, or pre-opened in UFW if using a non-standard port. | If SSH isn’t on port 22 and you don’t pre-open it, the installer’s firewall setup will lock you out. |
| Client app | Amnezia VPN >= 4.8.12.7 (all platforms). | AWG 2.0 parameters are not understood by older clients. The standard WireGuard client does not support AWG at all. |
â ïž Warning: LXC containers are not supported. If your VPS uses LXC virtualization, the DKMS kernel module build will fail. You must use KVM or bare-metal. Check with your provider if you’re unsure.
â ïž Warning: If your SSH runs on a non-standard port (anything other than 22), you must open it in UFW before running the installer:
sudo ufw allow YOUR_PORT/tcpReplace
YOUR_PORTwith your actual SSH port. The installer enables UFW with a default-deny policy â if your SSH port isn’t allowed, you’ll be locked out immediately.
ð¡ Tip: Wait 5â10 minutes after creating your VPS before running the installer. Cloud-init and background initialization processes can conflict with the
apt-getcalls the installer makes.
With your VPS ready and prerequisites confirmed, let’s deploy AmneziaWG 2.0 using the community installer script â the fastest and most transparent method.
ããŒã¯ãŒã
| ããŒã¯ãŒã | å®çŸ© |
|---|---|
| ð¡ïž AmneziaWG | WireGuardã®ãã©ãŒã¯ã§ããã±ããããããŒããµã€ãºãéä¿¡æéãã©ã³ãã åããŠãã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³(DPI)ã«å¯Ÿæããªãããåãå®èšŒæžã¿ã®æå·åãç¶æãããããã³ã«ããµãŒããŒäžã§åäœãããããã³ã«ã§ãã |
| ð AmneziaWG 2.0 | çŸåšã®ã¡ã€ã³ããŒãžã§ã³ã§ãåçããããŒç¯å²(åºå®å€ã®ä»£ããã«)ã䜿çšããããŒã¿ã¬ãã«ã®ããã£ã³ã°(S4)ã远å ãããã匷åãªDPIåé¿ã®ããã«ã«ã¹ã¿ã ãããã³ã«ã·ã°ããã£ãæã€ä»£æ¿ãã±ããããµããŒãããŠããŸãã |
| ð Deep Packet Inspection (DPI) | ISPããã³æ¿åºæ©é¢ããã±ããããããŒããµã€ãºããã³ãã·ã§ã€ã¯ãã¿ãŒã³ãåæããŠVPNãã©ãã£ãã¯ãèå¥ããã³ãããã¯ããããã«äœ¿çšãããããã¯ãŒã¯ãã£ã«ã¿ãªã³ã°æè¡ãAmneziaWGã¯ããã«å¯Ÿæããããã«ç¹å¥ã«èšèšãããŠããŸãã |
| â¡ WireGuard | å°ããªã³ãŒãããŒã¹ãšã«ãŒãã«ã¬ãã«ã®ããã©ãŒãã³ã¹ãåããé«éã§ææ°ã®VPNãããã³ã«ãåºå®ãã±ããæ§é ã«ãã£ãŠDPIã·ã¹ãã ã§å®¹æã«èå¥å¯èœã§ãããããã¯AmneziaWGã§å¯ŸåŠãããŠããŸãã |
| ð Self-hosted VPN | åçšãããã€ããŒã«ãµãã¹ã¯ã©ã€ãããã®ã§ã¯ãªããèªåã®ãµãŒããŒ(éåžžã¯VPS)ã«ãããã€ããŠç®¡çããVPNãããŒãèšå®ãã€ã³ãã©ã¹ãã©ã¯ãã£ãå¶åŸ¡ããŸãã |
| ð§ DKMS (Dynamic Kernel Module Support) | ã·ã¹ãã ã«ãŒãã«ãæŽæ°ããããšãã«ã«ãŒãã«ã¢ãžã¥ãŒã«ãèªåçã«åã³ã³ãã€ã«ããLinuxãã¬ãŒã ã¯ãŒã¯ãAmneziaWGã€ã³ã¹ããŒã©ãŒã¯DKMSã䜿çšããŠé«æ§èœã«ãŒãã«ã¢ãžã¥ãŒã«ããã«ãããŸãã |
| ð Obfuscation | VPNãã©ãã£ãã¯ãéåžžã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ã®ããã«èŠããããããã«ãã¹ãã³ã°ããæ £è¡ãAmneziaWGã¯ããããŒãã©ã³ãã åããããã£ã³ã°ã远å ãã代æ¿ãã±ãããéä¿¡ãããžã£ã³ã¯ãã±ãããçæããããšã§ããã©ã³ã¹ããŒãå±€ã§é£èªåããŸãã |
| ð Split tunneling | ç¹å®ã®ãã©ãã£ãã¯(äŸ:ãããã¯ããããµã€ã)ã®ã¿ãVPNãééãããã®ä»ã®ãã©ãã£ãã¯ãçŽæ¥æ¥ç¶ã䜿çšããã«ãŒãã£ã³ã°èšå®ãéšåçãªæ€é²ãããåœã§æçšã§ãã |
| ð¥ïž KVM vs LXC | KVMã¯AmneziaWGã®ãããªã«ã¹ã¿ã ã«ãŒãã«ã¢ãžã¥ãŒã«ãããŒãããããã«å¿ èŠãªå°çšã«ãŒãã«ãåããå®å šä»®æ³åã§ããLXCã¯ãã¹ãã®å ±æã«ãŒãã«ã䜿çšããã³ã³ããä»®æ³åã§ãã«ã¹ã¿ã ã¢ãžã¥ãŒã«ãããŒãã§ããŸããã |
| ðª CPS (Custom Protocol Signature) | AmneziaWG 2.0ã®æ©èœã§ãå®éã®ãã³ãã·ã§ã€ã¯ã®åã«ä»ã®ãããã³ã«(QUICãDNSãSIP)ãæš¡å£ãã代æ¿ãã±ãããéä¿¡ãããã©ãã£ãã¯ãéåžžã®ãã®ãšããŠåé¡ããããšã§DPIã·ã¹ãã ã誀解ãããŸãã |
ð æŽæ°(2026幎7æ): ãã®ã¬ã€ãã¯å ã®ãŠã©ãŒã¯ã¹ã«ãŒããã®ãŸãŸä¿æããŠããŸããã以äžã«ç€ºãããŠãããã³çããããã€ã³ã¹ããŒã©ãŒã¿ã°v5.8.1ã¯ãã¯ãææ°ã§ã¯ãããŸãããamneziawg-installerã®ææ°ãªãªãŒã¹ã¯v5.18.4ã§ãDebian 12ããã³13ã®ãµããŒããæ¢è£œã®ARM64ããã³Raspberry Piã«ãŒãã«ã¢ãžã¥ãŒã«ãUbuntu 25.10ããã³26.04ãã«ã¹ã±ãŒãã¢ãŒããããã³ãããªãã»ãã¥ãªãã£æ¹åã远å ããŠããŸãã
仿¥ãã®ã¬ã€ãã«åŸãå Žåã¯ãå€ããã³çããããã³ãã³ãã
wget https://raw.githubusercontent.com/bivlked/amneziawg-installer/v5.18.4/install_amneziawg_en.shã«çœ®ãæãããããããã€ããåã«ææ°ãªãªãŒã¹ããŒãžã§çŸåšã®ã¿ã°ã確èªããŠãã ããã
èªå·±ãããã€å AmneziaWG VPN ãµãŒã㌠â å®å šã¬ã€ã

AmneziaWG ã¯ãç¹å®ã®åé¡ã解決ããããã«èšèšããããããã³ã«ã§ããã€ãŸãããããã¯ãŒã¯ãç©æ¥µçã«ãããã¯ããããšããŠããç°å¢ã§ãWireGuard ã®é床ãå®çŸããã«ã¯ã©ãããã°ããããšããããšã§ãããã㯠Amnezia VPN ããŒã ã«ãã£ãŠäœæããã WireGuard ã®ãã©ãŒã¯ã§ãããå ã®ãããã³ã«ã«ã¯ãªãæ©èœãåããŠããŸãããã©ã³ã¹ããŒãå±€ãã©ã³ãã åããããšã§ããã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³ (DPI) ã·ã¹ãã ããããèå¥ã§ããªããªããŸããæå·åã¯å šãåããŸãŸã§ãããããã¯ãŒã¯äžã®ãã±ããã®èŠãç®ã ããå€ãããŸãã
VPN ãªããã¹ã±ãŒã·ã§ã³ (é£èªå) ã®åºå€§ãªé åã¯ãé·å¹Žã«ããã£ãŠè»æ¡ç«¶äºãšãªã£ãŠããŸããShadowsocksãVLESS+Realityãobfs4 ã䜿çšãã OpenVPN ãªã©ã®ããŒã«ã¯ãããŸããŸãªæ¹æ³ã§ãã©ãã£ãã¯ãåœè£ ããããšããŠããŸãããããã·ãšããŠæ©èœãããã®ããã«ãã³ãã«ãšããŠæ©èœãããã®ãé«ãããã©ãŒãã³ã¹ã³ã¹ãã䌎ããã®ããããŸããAmneziaWG ã¯ç¹å®ã®ããããå ããŠããŸãããã㯠WireGuard ã¬ãã«ã®ããã©ãŒãã³ã¹ãšçµã¿èŸŒã¿ã® DPI ä¿è·ãåããå®å šãª VPN ãã³ãã«ã§ããããã¹ãŠã 1 ã€ã®ããã±ãŒãžã«å«ãŸããŠããŸãããããŠãªãŒãã³ãœãŒã¹ã§ãããããç¬èªã®ãµãŒããŒã«ãããã€ã§ããŸãã
ãããããããå¿ èŠã«ãªãåé¡ããããŸããWireGuard ãã»ããã¢ããããŸããå®ç§ã«åäœããŸããé«éã§ãã¯ãªãŒã³ã§ãä¿¡é Œæ§ããããŸãããããŠããæ¥ãçªç¶åæ¢ããŸãããšã©ãŒã¡ãã»ãŒãžããªããã¿ã€ã ã¢ãŠãããªããæ¥ç¶æåŠããããŸããããã±ãããæ¶ããã ãã§ãããããå®éã® DPI ããããã³ã°ã®æ§åã§ãããã³ãã«ã¯ãŸã åäœããŠããŠãèšå®ã¯ãŸã æ£ãããäœãééããŠããŸãããããã¯æ¢ã«äžéšã®åœã®çŸå®ã§ãã

åŸæ¥ã®ä»£æ¿ææ®µã¯ãã®åé¡ãå®å šã«ã¯è§£æ±ºããŸãããShadowsocks ã¯ãããã·ã§ãããå®å šãª VPN ãã³ãã«ã§ã¯ãããŸãããDNS ãšé TCP ãã©ãã£ãã¯ã¯ãŸã ãªãŒã¯ããŸããobfs4 ã䜿çšãã OpenVPN ã¯æ©èœããŸãããçŽ 25% ã®ããã©ãŒãã³ã¹ãªãŒããŒãããããããŸããVLESS+Reality ã¯åŒ·åãªãªããã¹ã±ãŒã·ã§ã³ãæäŸããŸããããããã·ããŒã¹ã§èšå®ãè€éã§ããAmneziaWG ã¯ãã®ã®ã£ãããåããŸãããã㯠WireGuard ã¬ãã«ã®ããã©ãŒãã³ã¹ãšçµã¿èŸŒã¿ã® DPI ä¿è·ãåããå®å šãª VPN ãã³ãã«ã§ãã
ãã®ã¬ã€ãã§ã¯ãåäžã®ã³ãã¥ããã£ã€ã³ã¹ããŒã©ãŒã¹ã¯ãªããã䜿çšããŠã15 å以å ã«ä»»æã® KVM VPS äžã«å®å šã«æ©èœãã AmneziaWG 2.0 ãµãŒããŒããããã€ããæé ã説æããŸããæåŸã«ã¯ãä»»æã®ããã€ã¹ããæ¥ç¶ã§ããåäœãã VPN ãã³ãã«ã宿ããŸããæé ã¯ãããã€ããŒã«äŸåããŸãããAvaHost ãŸãã¯ä»ã®ãããã€ããŒããæäŸããããã®ã§ãã£ãŠããSSH ã¢ã¯ã»ã¹ãš root æš©éãæã€ä»»æã® VPS ã§æ©èœããŸãããã㯠SSH ãšåºæ¬ç㪠Linux ã³ãã³ãã䜿çšããããšã«æ £ããŠãããäžçŽã¬ãã«ã®æè¡ã¹ãã«ãæã€ãŠãŒã¶ãŒã察象ãšããŠããŸãã
å§ããåã«ã1 ã€ã®èª¬æããããŸããAmneziaWG ã¯ãããã³ã«ã§ããAmneziaVPN ã¯ã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ã§ãããããã«æ¥ç¶ããŸãããããã¯é¢é£ããŠããŸããç°ãªããŸãããã©ãŠã¶ã® TLS ã®ãããªãã®ã§ããæ¥ç¶ããã«ã¯ã¢ããªã±ãŒã·ã§ã³ãå¿ èŠã§ããããããã³ã«ã¯ãµãŒããŒã§å®è¡ããããã®ã§ãã
ããããäœãããããã€ããåã«ãAmneziaWG ã WireGuard ãšç°ãªããã®ã«ããŠãããã®ããã㊠DPI ãããªããç£èŠããŠãããšãã«ãã®éããéèŠã§ããçç±ãçè§£ããå¿ èŠããããŸãã
AmneziaWGãšã¯ïŒïŒã¡ã³ã¿ã«ã¢ãã«ïŒ
WireGuardã¯ãã®èšèšã®åªé ãã§ç¥ãããŠããŸããã³ãŒãããŒã¹ãå°ãããææ°ã®æå·åã䜿çšããLinuxã«ãŒãã«ã§å®è¡ããããããã»ãŒãã€ãã£ãã®ããã©ãŒãã³ã¹ãå®çŸããŸãããããããã®åªé ãã«ã¯å¯èŠæ§ã®åé¡ããããŸãããã¹ãŠã®WireGuardãã±ããã¯åãåºå®ããããŒæ§é ãåãåºå®ãã±ãããµã€ãºãåããã³ãã·ã§ã€ã¯ãã¿ãŒã³ãæã£ãŠããŸãããã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³ïŒDPIïŒã·ã¹ãã ã«ãšã£ãŠãWireGuardãã³ãã«ã¯ããŒã³ãŒãã®ããã«æç¢ºãªã·ã°ããã£ãæã£ãŠããŸããDPIããã€ã¹ããã®ã·ã°ããã£ãåŠç¿ãããšãããŒãããããã¯ãããæ¥ç¶ãéãããããããšãªãããã¹ãŠã®ãã±ãããããããã§ããŸãã

AmneziaWGã¯Amnezia VPNããŒã ã«ãã£ãŠäœæãããWireGuard-Goã®ãã©ãŒã¯ã§ããWireGuardã®ã¢ãŒããã¯ãã£ã®åçŽæ§ãç¶æ¿ããŠããŸããåãCurve25519éµäº€æãåãChaCha20-Poly1305æå·åãåãNoise IKãã³ãã·ã§ã€ã¯ã§ãããã¹ãŠã®æå·åã¯å€ããããæ€èšŒæžã¿ã§ããAmneziaWGã倿Žããã®ã¯ãã©ã³ã¹ããŒãå±€ã§ãããã±ããããããŒããã±ãããµã€ãºãã¿ã€ãã³ã°ãã¿ãŒã³ã§ãã
ãã®ããã«èããŠãã ãããWireGuardã¯åžžã«åãå¶æãçãŠããé éå¡ã®ãããªãã®ã§ããé«éã§ä¿¡é Œæ§ããããå¹ççã§ããããããéè·¯ãèŠãŠãã誰ãããã®å¶æãèªèããããšãåŠã³ããã¹ãŠã®ãã§ãã¯ãã€ã³ãã§é éå¡ãæ¢ããããšãã§ããŸããAmneziaWGã¯åãããã±ãŒãžãéã¶åãé éå¡ã§ããããã¹ãŠã®ãã§ãã¯ãã€ã³ãã§å¶æãå€ããŸããåã人ç©ãåãè·ç©ããŸã£ããç°ãªãå€èгã§ãã
ããŒãžã§ã³å±¥æŽã¯éèŠã§ããAmneziaWG 1.xã¯WireGuardã®åºå®å€ãšç°ãªãã«ã¹ã¿ã ããããŒãå°å ¥ããŸãããããã¯ãã°ããã®é圹ã«ç«ã¡ãŸããããDPIã·ã¹ãã ã¯é©å¿ããŸããã2025幎åŸåã«ãªãªãŒã¹ãããAmneziaWG 2.0ã¯ããã¹ãŠãã©ã³ãã åããŸããããããŒã¯ãã±ããããšã«å€ãããããã£ã³ã°ã¯ã¡ãã»ãŒãžããšã«ç°ãªãã代æ¿ãã±ããã¯å®éã®ãã³ãã·ã§ã€ã¯ã®åã«ä»ã®ãããã³ã«ãæš¡å£ããŸããåAmneziaWG 2.0ãµãŒããŒã¯ç¬èªã®äžæã®ãã©ã¡ãŒã¿ã»ãããçæãããããæ€åºã®ããã®æ®éçãªã·ã°ããã£ã¯ãããŸãããåãµãŒããŒã¯ç¬èªã®æ¹èšã話ããŸãã
ãã¹ãŠã®é£èªåãã©ã¡ãŒã¿ããŒãã«èšå®ãããŠããå ŽåãAmneziaWGã¯WireGuardãšåãããã«åäœããŸãããããã³ã«ã¬ãã«ã§å®å šã«åŸæ¹äºææ§ããããŸããããããã¢ã¯ãã£ããªãã©ã¡ãŒã¿ïŒããã©ã«ãèšå®ïŒã䜿çšãããšãWireGuardãå®çŸã§ããªããã®ã«ãªããŸããDPIã·ã¹ãã ãèå¥ããã®ã«èŠåŽããé«éVPNãã³ãã«ã§ãã
ã§ã¯ãAmneziaWGã¯ãã©ãã£ãã¯ãã©ã®ããã«æ£ç¢ºã«æå·åããã®ã§ããããïŒDPIãç²ç®ã«ãã4ã€ã®ã¬ãã«ã®é£èªåãšããããã
AmneziaWG ã DPI ããé ããä»çµã¿ïŒé床äœäžãªãïŒ
AmneziaWG 2.0 ã¯ã飿ºããŠæ©èœãã 4 ã€ã®ã¬ãã«ã®é£èªåã䜿çšããŸããåã¬ãã«ã¯ãDPI ã·ã¹ãã ã VPN ãã©ãã£ãã¯ãèå¥ããç°ãªãæ¹æ³ãã¿ãŒã²ããã«ããŠããŸããããããçµã¿åãããããšã§ãåãµãŒããŒã®ãã©ãã£ãã¯ãäžæã«ãªããŸãã
åçããããŒïŒH1âH4ïŒ
WireGuard ã¯åºå®ã® 32 ããã ã¡ãã»ãŒãžã¿ã€ãèå¥åã䜿çšããŸãïŒ
- 1 â åæåçš
- 2 â ã¬ã¹ãã³ã¹çš
- 3 â ã¯ãããŒä»ãã¬ã¹ãã³ã¹çš
- 4 â ããŒã¿çš
DPI ããã€ã¹ããã©ãã£ãã¯ãã¹ãã£ã³ããéããããã®å€ãåçŽã«æ¢ããŸããAmneziaWG 2.0 ã¯ãååºå®å€ãæå®ç¯å²ããéžæãããã©ã³ãã ãªæ°å€ã«çœ®ãæããŸããåæåããããŒïŒH1ïŒã¯ 234567 ãã 345678 ã®ä»»æã®å€ã«ãªããŸããã¬ã¹ãã³ã¹ããããŒïŒH2ïŒã¯ 3456789 ãã 4567890 ã®ç¯å²ã«ãªããŸãããããã®ç¯å²ã¯éè€ããŸããããããã³ã«ã¯å éšçã«ãã±ããã¿ã€ããåºå¥ããå¿ èŠãããããã§ãããã ããå€éšã®èгå¯è ã«ãšã£ãŠã¯ãåºå®ãããããããŒå€ããããŸãããåãã±ããã¯åã®ãã±ãããšç°ãªããŸãã
ã©ã³ãã ããã£ã³ã°ïŒS1âS4ïŒ
WireGuard ã®åæåãã±ããã¯åžžã«ã¡ããã© 148 ãã€ãã§ãããã®ã¬ã¹ãã³ã¹ã¯åžžã«ã¡ããã© 92 ãã€ãã§ãããããã®åºå®ãµã€ãºã¯å¥ã®ãã£ã³ã¬ãŒããªã³ãã§ããAmneziaWG ã¯åãã±ããã¿ã€ãã«ã©ã³ãã ããã£ã³ã°ã远å ããŸãïŒåæå㯠148+S1 ãã€ãã«ãªããã¬ã¹ãã³ã¹ã¯ 92+S2 ãã€ãã«ãªããã¯ãããŒä»ãã¬ã¹ãã³ã¹ã¯ 64+S3 ãã€ãã«ãªããåããŒã¿ãã±ãã㯠S4 ãã€ãã®ããã£ã³ã°ãåãåããŸããS3 ãš S4 ã¯ããŒãžã§ã³ 2.0 ã§æ°ãã远å ãããŸãããS4 ã¯æãéèŠãªè¿œå æ©èœã§ãããã¹ãŠã®ããŒã¿ãã±ããã«åœ±é¿ãäžãããããã»ãã·ã§ã³ã¬ãã«ã®ãã©ãã£ãã¯åæãã¯ããã«é£ãããªããŸãã
1 ã€ã®éèŠãªå¶çŽããããŸãïŒS1+56 㯠S2 ãšçãããŠã¯ãããŸãããåæåãšã¬ã¹ãã³ã¹ã®å ã®ãµã€ãºå·®ã 56 ãã€ãïŒ148â92ïŒã§ãããããããã£ã³ã°å€ããã®å·®ãã¡ããã©è£æ£ãããšã2 ã€ã®ããã£ã³ã°æžã¿ãã±ãããåããµã€ãºã«ãªããAmneziaWG ãæé€ããããšããŠãããã£ã³ã¬ãŒããªã³ããåçŸãããŸããã€ã³ã¹ããŒã©ãŒã®ãã©ã¡ãŒã¿ãžã§ãã¬ãŒã¿ã¯èªåçã«ãã®å¶çŽã確ä¿ããŸãã
ã«ã¹ã¿ã ãããã³ã«ã·ã°ããã£ïŒI1âI5ïŒ
å®éã®ãã³ãã·ã§ã€ã¯ãå§ãŸãåã«ãAmneziaWG ã¯ã©ã€ã¢ã³ãã¯ãä»ã®ãããã³ã«ïŒQUICãDNSãSIPããŸãã¯ã«ã¹ã¿ã ãã€ããã¿ãŒã³ïŒãæš¡å£ããæå€§ 5 ã€ã®ä»£æ¿ãã±ãããéä¿¡ããŸãããµãŒããŒã¯ãããã®ãã±ãããå®å šã«ç¡èŠããŸããå®éã®ãã³ãã·ã§ã€ã¯ãåŸ ã€ã ãã§ãã
- ã·ã³ãã«èšå®ïŒ 128 ã©ã³ãã ãã€ã <r 128> ãéä¿¡ããŸãã
- è€éãªèšå®ïŒ QUIC æ¥ç¶ãéå§ããŠããããã«èŠãããã€ãïŒ<b 0xc000000001><r 64><t>ïŒã Unix ã¿ã€ã ã¹ã¿ã³ãä»ãã§éä¿¡ããŸãã
DPI ã·ã¹ãã ãã»ãã·ã§ã³ã®éå§ã芳å¯ããå Žåãæåã®ãã±ããã¯éåžžã® Web ãã©ãã£ãã¯ã®ããã«èŠããŸãã
ãžã£ã³ã¯ãã±ããïŒJcãJminãJmaxïŒ
代æ¿ãã±ããã®åŸãã¯ã©ã€ã¢ã³ãã¯ã«ã¹ã¿ãã€ãºå¯èœãªæ°ã®ãžã£ã³ã¯ãã±ããïŒJmin ãã Jmax ãŸã§ã®ã©ã³ãã ãµã€ãºã®çŽç²ãªãã€ãºïŒãéä¿¡ããŸãããããã®ãã±ããã¯ã»ãã·ã§ã³éå§ã®ã¿ã€ãã³ã°ãšãµã€ãºãããã¡ã€ã«ããŒãããDPI ã·ã¹ãã ãå®éã®ãã³ãã·ã§ã€ã¯ã®éå§äœçœ®ãç¹å®ããããšãé£ããããŸãã
é床ã«é¢ãã質å
ã€ã³ã¿ãŒãããäžã«æµéããŠããæ°åããããŸãïŒAmneziaWG ã®ãªãŒããŒããã㯠65% ã§ãããã®æ°åã¯å®åšããŸããããŠãŒã¶ãŒã¹ããŒã¹ã® Go å®è£ ãæããŠããŸããã«ãŒãã«ã¢ãžã¥ãŒã«ã§ã¯ãããŸããããã®ã¬ã€ãã§äœ¿çšãããŠããã³ãã¥ããã£ã€ã³ã¹ããŒã©ãŒã¯ DKMS ã«ãŒãã«ã¢ãžã¥ãŒã«ããã«ãããã«ãŒãã«ã¢ãžã¥ãŒã«ã¯å šäœã§ 12% æªæºã®ãªãŒããŒãããã远å ããŸããå®éã®ãã¹ãã§ã¯ãã 3% ã«è¿ãã§ããæ€é²ãããŠããªããããã¯ãŒã¯ã§ã¯ãWireGuard ãéããŠçŽ 95 MbpsãAmneziaWG 2.0 ãéã㊠92 Mbps ã衚瀺ãããŸããæ€é²ããããããã¯ãŒã¯ã§ã¯ãæ¯èŒã¯ 92 Mbps 察ãŒãã§ãã
次ã®è¡šã¯ãã€ã³ã¹ããŒã©ãŒãèªåçã«çæãããã©ã¡ãŒã¿ããŸãšããŠããŸãïŒ
| ãã©ã¡ãŒã¿ | çæç¯å² | äŸå€ |
|---|---|---|
| JcïŒãžã£ã³ã¯ãã±ããæ°ïŒ | 4â8 | 6 |
| JminïŒæå°ãžã£ã³ã¯ãµã€ãºïŒ | 40â89 | 55 |
| JmaxïŒæå€§ãžã£ã³ã¯ãµã€ãºïŒ | Jmin+100 ãã Jmin+500 | 380 |
| S1ïŒåæåããã£ã³ã°ïŒ | 15â150 | 72 |
| S2ïŒã¬ã¹ãã³ã¹ããã£ã³ã°ïŒ | 15â150ãS1+56â S2 | 56 |
| S3ïŒã¯ãããŒããã£ã³ã°ïŒ | 8â55 | 32 |
| S4ïŒããŒã¿ããã£ã³ã°ïŒ | 4â27 | 16 |
| H1ïŒåæåããããŒç¯å²ïŒ | éè€ãªãã® uint32 | 234567-345678 |
| H2ïŒã¬ã¹ãã³ã¹ããããŒç¯å²ïŒ | éè€ãªãã® uint32 | 3456789-4567890 |
| H3ïŒã¯ãããŒããããŒç¯å²ïŒ | éè€ãªãã® uint32 | 56789012-67890123 |
| H4ïŒããŒã¿ããããŒç¯å²ïŒ | éè€ãªãã® uint32 | 456789012-567890123 |
| I1ïŒCPS ãã±ããïŒ | <r N> åœ¢åŒ | <r 128> |
ãããã®ãã©ã¡ãŒã¿ãæåã§èšå®ããå¿ èŠã¯ãããŸãããã€ã³ã¹ããŒã©ãŒã¯å¶çŽãæºããæå·çã«ã©ã³ãã ãªå€ãæ¯åçæããŸãã
é£èªåã®ä»çµã¿ãããã£ãã®ã§ãæ€èšããŠããä»£æ¿æ¡ãš AmneziaWG ãã©ã®ããã«æ¯èŒãããããèŠãŠã¿ãŸãããã
AmneziaWG vs ä»£æ¿æ¡ â ã¯ã€ãã¯æææ±ºå®ã¬ã€ã

| WireGuard | AmneziaWG 2.0 | OpenVPN+obfs4 | Shadowsocks | VLESS+Reality | |
|---|---|---|---|---|---|
| DPIèæ§ | äœ | é« | äžçšåºŠ | äžçšåºŠ | éåžžã«é«ã |
| é床ãªãŒããŒããã | ~4% | <12% (å®éã®æ¡ä»¶ã§ã¯~3%) | ~25% | ~8% | ~10% |
| ãã«VPNãã³ãã« | ã¯ã | ã¯ã | ã¯ã | ããã (ãããã·) | ããã (ãããã·) |
| ã«ãŒãã«ã§å®è¡ | ã¯ã | ã¯ã (DKMS) | ããã | ããã | ããã |
| ã»ããã¢ããã®è€éã | äœ | äœ (ã€ã³ã¹ããŒã©ãŒä»ã) | é« | äžçšåºŠ | é« |
| ãã©ã³ã¹ããŒã | UDP | UDP | TCP/UDP | TCP | TCP |
æææ±ºå®ã«ãŒã«ã¯ã·ã³ãã«ã§ãïŒ
- ããªãã®åœã«DPIããªãïŒ éåžžã®WireGuardã䜿çšããŠãã ãããããç°¡åã§ãããåºããšã³ã·ã¹ãã ããããŸãã
- æå€§DPIä¿è·ãå¿ èŠã§ããããã·ãæ°ã«ããªãïŒ VLESS+Realityã¯é£èªåã®æåŒ·ãªãã·ã§ã³ã§ããããã«ãã³ãã«ã§ã¯ãããŸããã
- é床ãšãã«ãã³ãã«é£èªåã®äž¡æ¹ãå¿ èŠïŒ AmneziaWG 2.0ã¯ããã«VPNãã³ãã«ã§å®éã®DPIä¿è·ãåããWireGuardã¬ãã«ã®ããã©ãŒãã³ã¹ãæäŸããå¯äžã®ãªãã·ã§ã³ã§ãã
- æ¢ã«OpenVPN+obfs4ã䜿çšããŠããŠããŸã æ©èœããŠããïŒ ç·æ¥ã®åãæ¿ãå¿ èŠã¯ãããŸããããAmneziaWGã¯é¡èã«é«éã«ãªããŸãã
ãã®èšäºãAmneziaWGã«çŠç¹ãåœãŠãŠããçç±ã¯ããã«ãã³ãã«ãã«ãŒãã«ã¬ãã«ã®ããã©ãŒãã³ã¹ãçµã¿èŸŒã¿é£èªåã
éå§ããåã«å¿ èŠãªãã®
ã€ã³ã¹ããŒã©ãŒãå®è¡ããåã«ãç°å¢ã以äžã®èŠä»¶ãæºãããŠããããšã確èªããŠãã ãã:
| èŠä»¶ | 詳现 | çç± |
|---|---|---|
| OS | Ubuntu 24.04 LTS (ã¯ãªãŒã³ã€ã³ã¹ããŒã«)ãUbuntu 25.10 ã¯å®éšçã§ããDebian 12/13 ã¯åäœããŸãããcurl ã®äºåã€ã³ã¹ããŒã«ãå¿ èŠãªå ŽåããããŸãã | ã€ã³ã¹ããŒã©ãŒã¯ Ubuntu 24.04 ã§ãã¹ãæžã¿ã§å®å šã«ãµããŒããããŠããŸãã |
| VPS ã¹ãã㯠| 1 vCoreã1 GB RAMã25 GB ã¹ãã¬ãŒãžãæé¡ $3â5 ã®ãã©ã³ã§ããã°é©åã§ãã | ã€ã³ã¹ããŒã©ãŒã¯ DKMS ãã«ãäžã«çŽ 2 GB ã®ãã£ã¹ã¯å®¹éãšçŽ 1 GB ã® RAM ãå¿ èŠãšããŸããåäœäžã® VPN ã¯æå°éã®ãªãœãŒã¹ã䜿çšããŸãã |
| ä»®æ³å | KVM (OpenVZ ã LXC ã§ã¯ãªã)ã | AmneziaWG 㯠DKMS çµç±ã§ã«ãŒãã«ã¢ãžã¥ãŒã«ãããŒãããŸããLXC ã¯ãã¹ãã«ãŒãã«ãå ±æããã«ã¹ã¿ã ã¢ãžã¥ãŒã«ãããŒãã§ããŸããã |
| SSH ã¢ã¯ã»ã¹ | root ãŸãã¯ãã¹ã¯ãŒã/ããŒèªèšŒãæã€ sudo ãŠãŒã¶ãŒã | ã€ã³ã¹ããŒã©ãŒã¯ root ãšããŠå®è¡ããå¿ èŠããããŸãã |
| SSH ããŒã | ããã©ã«ã 22ããŸãã¯éæšæºããŒãã䜿çšããå Žå㯠UFW ã§äºåã«éæŸã | SSH ãããŒã 22 ã§å®è¡ãããŠããªãå Žåãäºåã«éæŸããŠããªããšãã€ã³ã¹ããŒã©ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«èšå®ã«ãã£ãŠãããã¯ãããŸãã |
| ã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ | Amnezia VPN >= 4.8.12.7 (å šãã©ãããã©ãŒã )ã | AWG 2.0 ãªãã·ã§ã³ã¯å€ãã¯ã©ã€ã¢ã³ãã§ã¯èªèãããŸãããæšæº WireGuard ã¯ã©ã€ã¢ã³ã㯠AWG ããµããŒãããŠããŸããã |
â ïž èŠå: LXC ã³ã³ããã¯ãµããŒããããŠããŸãããVPS ã LXC ä»®æ³åã䜿çšããŠããå ŽåãDKMS ã«ãŒãã«ã¢ãžã¥ãŒã«ãã«ãã¯å€±æããŸããKVM ãŸãã¯ãã¢ã¡ã¿ã«ã䜿çšããå¿ èŠããããŸããäžç¢ºããªå Žåã¯ãããã€ããŒã«ç¢ºèªããŠãã ããã
â ïž èŠå: SSH ãéæšæºããŒã (22 以å€) ã§å®è¡ãããŠããå Žåãã€ã³ã¹ããŒã©ãŒãå®è¡ããåã« UFW ã§éæŸããå¿ èŠããããŸã
sudo ufw allow YOUR_PORT/tcp
YOUR_PORT ãå®éã® SSH ããŒãã«çœ®ãæããŠãã ãããã€ã³ã¹ããŒã©ãŒã¯ããã©ã«ãããªã·ãŒã§ UFW ãå«ã¿ãŸã â SSH ããŒããèš±å¯ãããŠããªãå Žåãããã«ãããã¯ãããŸãã
ð¡ ãã³ã: VPS ãäœæããŠããã€ã³ã¹ããŒã©ãŒãå®è¡ãããŸã§ 5ïœ10 ååŸ æ©ããŠãã ãããcloud-init ãšããã¯ã°ã©ãŠã³ãåæåããã»ã¹ãã€ã³ã¹ããŒã©ãŒãè¡ã apt-get åŒã³åºããšç«¶åããå¯èœæ§ããããŸãã
VPS ã®æºåãã§ããåææ¡ä»¶ã確èªãããããã³ãã¥ããã£ã€ã³ã¹ããŒã©ãŒã¹ã¯ãªããã䜿çšã㊠AmneziaWG
æ¹æ³1 â CLIã€ã³ã¹ããŒã©ãŒã§ãããã€ïŒæšå¥šïŒ
ããã¯ãã©ã€ããªã€ã³ã¹ããŒã«æ¹æ³ã§ããããŒãžã§ã³åºå®ãããã€ã³ã¹ããŒã©ãŒã¹ã¯ãªãããããŠã³ããŒãããrootãšããŠå®è¡ããŠã8ã€ã®èªååãããã¹ãããïŒäºæ³ããã2åã®åèµ·åãå«ãïŒãé²ãããšãå®å šã«æ§æãããAmneziaWG 2.0ãµãŒããŒã宿ããŸããã€ã³ã¹ããŒã©ãŒã¯ãã¹ãŠãåŠçããŸãïŒããã±ãŒãžã€ã³ã¹ããŒã«ãã«ãŒãã«ã¢ãžã¥ãŒã«ã³ã³ãã€ã«ããã¡ã€ã¢ãŠã©ãŒã«èšå®ããã©ã¡ãŒã¿çæããµãŒãã¹èµ·åã
6.1 â SSHã§VPSã«æ¥ç¶
ã¿ãŒããã«ãéãããµãŒããŒã«æ¥ç¶ããŸãïŒ
ssh root@<SERVER_IP>
<SERVER_IP>ãVPSã®å®éã®ãããªãã¯IPã¢ãã¬ã¹ã«çœ®ãæããŠãã ããããããã€ããŒãérootãŠãŒã¶ãŒãæäŸããå Žåã¯ããã®ãŠãŒã¶ãŒã§ãã°ã€ã³ããŠãããšã¹ã«ã¬ãŒãããŸãïŒ
ssh <username>@<SERVER_IP>
sudo -i
Ubuntu 24.04ãŠã§ã«ã«ã ãããŒã®åŸã«rootããã³ããã衚瀺ãããã¯ãã§ãïŒ
Welcome to Ubuntu 24.04 LTS (GNU/Linux 6.8.0-xx-generic x86_64)
...
root@vps:~#
6.2 â ã€ã³ã¹ããŒã©ãŒãããŠã³ããŒãããŠå®è¡
ã€ã³ã¹ããŒã©ãŒã¹ã¯ãªãããããŠã³ããŒãããå®è¡å¯èœã«ããŠå®è¡ããŸãïŒ
wget https://raw.githubusercontent.com/bivlked/amneziawg-installer/v5.8.1/install_amneziawg_en.sh
chmod +x install_amneziawg_en.sh
sudo bash ./install_amneziawg_en.sh
URLã¯v5.8.1ã«ããŒãžã§ã³åºå®ãããŠããŸã â 2026幎4ææç¹ã§ã®ææ°ãªãªãŒã¹ã§ããããã¯ãµãã©ã€ãã§ãŒã³ã»ãã¥ãªãã£ã§ãïŒãªããžããªãæŽæ°ãããŠããŠããããŠã³ããŒããããã¹ã¯ãªããããã¹ãæžã¿ããŒãžã§ã³ãšäžèŽããããšãä¿èšŒããŸãã
ã€ã³ã¹ããŒã©ãŒã¯ã·ã¹ãã ãã§ãã¯ãéå§ããŸãïŒ
============================================
AmneziaWG 2.0 Installer v5.8.1
============================================
Checking system requirements...
OS: Ubuntu 24.04 LTS â OK
Virtualization: KVM â OK
RAM: 1024 MB â OK
Disk: 25 GB free â OK
ãã§ãã¯ã倱æããå Žåãã€ã³ã¹ããŒã©ãŒã¯åæ¢ããŠçç±ãéç¥ããŸããåé¡ãä¿®æ£ããŠãã³ãã³ããåå®è¡ããŠãã ããã
6.3 â ã€ã³ã¹ããŒã©ãŒããã³ãããé²ãã
ã€ã³ã¹ããŒã©ãŒã¯åèµ·ååŸã®åéãµããŒãä»ãã®8ã¹ãããã¹ããŒããã·ã³ã§ããé²è¡ç¶æ³ã/root/awg/awgsetup_cfg.initã«ä¿åããããããµãŒããŒãåèµ·åããå Žåã¯åãã³ãã³ããå®è¡ããã°ãäžæãããšããããåéããŸãã
ã¹ããã0ïŒåæå â ã€ã³ã¹ããŒã©ãŒã¯OSãä»®æ³åã¿ã€ããRAMããã£ã¹ã¯å®¹éããã§ãã¯ããŸãã/root/awg/äœæ¥ãã£ã¬ã¯ããªãäœæãã䞊åå®è¡ãé²ãããã®ããã¯ãã¡ã€ã«ãèšå®ããŸãã
ã¹ããã1ïŒã·ã¹ãã æŽæ°ãšããã±ãŒãžã€ã³ã¹ããŒã« â ã€ã³ã¹ããŒã©ãŒã¯apt-get update && apt-get upgrade -yãå®è¡ããŸãããã®åŸãAmneziaWGãDKMSãLinuxããããŒãUFWãFail2BanãQRã³ãŒãçæããŒã«ãããã³ãã®ä»ã®äŸåé¢ä¿ãã€ã³ã¹ããŒã«ããŸãã
ð æ³šïŒã€ã³ã¹ããŒã©ãŒã¯ãæå°éã®VPSã€ã³ã¹ã¿ã³ã¹ã§ãªãœãŒã¹ãæ¶è²»ããããã€ãã®ããã¯ã°ã©ãŠã³ããµãŒãã¹ãåé€ããŸãïŒsnapdãmodemmanagerãnetworkd-dispatcherãunattended-upgradesãpackagekitãlxd-agent-loaderãudisks2ãããã¯æå³çã§æå°éã®VPNããŒãã§ã¯å®å šã§ãããæ±çšç°å¢ãç Žå£ããå¯èœæ§ããããŸãã
ã¹ããã1ãå®äºãããšãã€ã³ã¹ããŒã©ãŒã¯åèµ·åããªã¯ãšã¹ãããŸãïŒ
Reboot required. Reboot now? [y/n]:
yãå ¥åããŠEnterããŒãæŒããŸãããµãŒããŒãèµ·åããããå床SSHã§ãã°ã€ã³ããŠåãã³ãã³ããåå®è¡ããŸãïŒ
sudo bash ./install_amneziawg_en.sh
ã¹ã¯ãªããã¯ä¿åãããç¶æ ãèªã¿èŸŒã¿ãããã³ãããå床å°ããããšãªãã¹ããã2ã«é²ã¿ãŸãã
ã¹ããã2ïŒDKMSã«ãŒãã«ã¢ãžã¥ãŒã«ãã«ã â ã€ã³ã¹ããŒã©ãŒã¯çŸåšã®ã«ãŒãã«ã«å¯ŸããŠAmneziaWGã«ãŒãã«ã¢ãžã¥ãŒã«ãã³ã³ãã€ã«ããDKMSã«ç»é²ããŠå°æ¥ã®ã«ãŒãã«æŽæ°æã«èªåçã«åæ§ç¯ãããããã«ããŸãïŒ
Step 2: Building AmneziaWG kernel module via DKMS...
Creating symlink /var/lib/dkms/amneziawg/2.0/source -> /usr/src/amneziawg-2.0
DKMS: add completed.
Kernel preparation completed.
Building module:
make -C /lib/modules/6.8.0-xx-generic/build M=/var/lib/dkms/amneziawg/2.0/build modules
DKMS: build completed.
DKMS: install completed.
2çªç®ã®åèµ·åããªã¯ãšã¹ããããŸããyãå ¥åããŠEnterããŒãæŒããŸãã
ð æ³šïŒã€ã³ã¹ããŒã«äžã®2åã®åèµ·åã¯æ£åžžã§äºæ³ãããŠããŸããæåã®ãã®ã¯æ°ããã«ãŒãã«ããããŒãããŒããã2çªç®ã®ãã®ã¯æ°ããæ§ç¯ãããã«ãŒãã«ã¢ãžã¥ãŒã«ãã¢ã¯ãã£ãåããŸããã¹ã¯ãªããã¯åèµ·åéã§ç¶æ ãä¿åããŸã â äœã倱ãããŸããã
2çªç®ã®åèµ·ååŸãSSHã§å床ãã°ã€ã³ããŠã€ã³ã¹ããŒã©ãŒãããäžåºŠå®è¡ããŸãïŒ
sudo bash ./install_amneziawg_en.sh
ã¹ããã3ïŒåèµ·ååŸã¢ãžã¥ãŒã«æ€èšŒ â ã¹ã¯ãªããã¯ã«ãŒãã«ã¢ãžã¥ãŒã«ãããŒããããŠããããšãæ€èšŒããŸãïŒlsmod | grep amneziawgïŒãäœããã®çç±ã§DKMSãã«ãã倱æããå Žåãããé«ããªãŒããŒãããã«ã€ããŠã®èŠåã䌎ã£ãŠãŠãŒã¶ãŒã¹ããŒã¹Goå®è£ ã«ãã©ãŒã«ããã¯ããŸãã
ã¹ããã4ïŒãã¡ã€ã¢ãŠã©ãŒã«èšå® â UFWã¯ããã©ã«ãæåŠåä¿¡ããªã·ãŒã§æå¹ã«ãªããŸããã€ã³ã¹ããŒã©ãŒã¯ããŒã22ã®SSHã¬ãŒãå¶éã«ãŒã«ã远å ããVPNããŒããUDPãã©ãã£ãã¯çšã«éããawg0ã€ã³ã¿ãŒãã§ãŒã¹ã®ã«ãŒãã£ã³ã°ã«ãŒã«ãèšå®ããŸãã
ã¹ããã5ïŒç®¡çã¹ã¯ãªããã®ããŠã³ããŒã â ã¯ã©ã€ã¢ã³ã管çã¹ã¯ãªããïŒmanage_amneziawg.shããã³awg_common.shïŒã¯/root/awg/ã«ãªãŒããŒã®ã¿ã®æš©éïŒ700ïŒã§ããŠã³ããŒããããŸããããããv5.8.1ã«ããŒãžã§ã³åºå®ãããŠããŸãã
ã¹ããã6ïŒã€ã³ã¿ã©ã¯ãã£ãèšå® â ã€ã³ã¹ããŒã©ãŒã¯4ã€ã®è³ªåãããŸãïŒ
- UDPããŒãïŒããã©ã«ãïŒ39743ãç¯å²1024â65535ïŒãããã©ã«ãã¯ã©ã³ãã ãªé«ããŒãã§ã â ISPãé«UDPããŒãããããã¯ããããšãç¥ãããŠããå Žåãé€ããä¿æããŠãã ããã
- ãã³ãã«ãµããããïŒããã©ã«ãïŒ10.9.9.1/24ïŒãããã¯å éšVPNãããã¯ãŒã¯ã§ãããµãŒããŒã¯.1ãååŸããã¯ã©ã€ã¢ã³ãã¯.2ãã.254ãååŸããæå€§253ã¯ã©ã€ã¢ã³ãããµããŒãããŸãã
- IPv6ãç¡å¹åïŒããã©ã«ãïŒYïŒãæšå¥š â IPv6ãç¡å¹åãããšIPv6ã«ãŒãã§ãã³ãã«å€ã®ãã©ãã£ãã¯ãªãŒã¯ãé²ããŸãã
- ã«ãŒãã£ã³ã°ã¢ãŒãïŒãã¹ãŠã®ãã©ãã£ãã¯ã®å Žåã¯1ãAmnezia List + DNSã®å Žåã¯2ïŒæšå¥šïŒãã«ã¹ã¿ã ãããã¯ãŒã¯ã®å Žåã¯3ãéžæããŸããã¢ãŒã2ã¯ãããã¯ããããããªãã¯IPã¬ã³ãžãšDNSã®ã¿ãVPNçµç±ã§ã«ãŒãã£ã³ã°ããããŒã«ã«ãããã¯ãŒã¯ã¢ã¯ã»ã¹ãé«éã§çŽæ¥ã«ä¿ã¡ãŸãã
ð¡ ãã³ãïŒMTUã¯ããã©ã«ãã§1280ã«èšå®ãããŠããŸããããã¯æå°IPv6 MTUã§ãããã¢ãã€ã«ããã³ã»ã«ã©ãŒãããã¯ãŒã¯ã«ãšã£ãŠéèŠã§ããiOSã¯Path MTU Discoveryã«å³å¯ã§ãããã»ã«ã©ãŒãããã¯ãŒã¯ã¯WireGuardã®ããã©ã«ã1420ããäœãæå¹MTUãæã€ããšããããããŸããããã1280ã®ãŸãŸã«ããŠãã ããã
ã¹ããã7ïŒãµãŒãã¹éå§ â ã€ã³ã¹ããŒã©ãŒã¯/etc/amnezia/amneziawg/awg0.confã§ãµãŒããŒèšå®ãçæãã/root/awg/ã«2ã€ã®ããã©ã«ãã¯ã©ã€ã¢ã³ãèšå®ïŒmy_phoneããã³my_laptopïŒãäœæããQRã³ãŒããçæããawg-quick@awg0 systemdãµãŒãã¹ãéå§ããŸãã
ã¹ããã8ïŒå®äº â æåã¡ãã»ãŒãžã衚瀺ãããŸãïŒ

ã€ã³ã¹ããŒã©ãŒã¯ãã¹ãŠã®AmneziaWG 2.0é£èªåãã©ã¡ãŒã¿ãèªåçã«çæããŸãããããã«è§Šããå¿ èŠã¯ãããŸãããåãµãŒããŒã¯äžæã®å€ã»ãããååŸããŸã â DPIã·ã¹ãã ãæ€åºããããã®æ®éçãªãã£ã³ã¬ãŒããªã³ãã¯ãããŸããã
6.4 â ã€ã³ã¹ããŒã«åŸã®ã¯ã©ã€ã¢ã³ã管ç
/root/awg/manage_amneziawg.shã®ç®¡çã¹ã¯ãªããã¯ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã©ã€ããµã€ã¯ã«æäœãåŠçããŸããå¿ é ã³ãã³ãã¯æ¬¡ã®ãšããã§ãïŒ
æ°ããã¯ã©ã€ã¢ã³ãã远å ïŒ
sudo bash /root/awg/manage_amneziawg.sh add my_desktop
ããã¯.confãã¡ã€ã«ãQRã³ãŒããæ°ããã¯ã©ã€ã¢ã³ãçšã®.vpnuriãã¡ã€ã«ãçæããŸãããµãŒããŒèšå®ã¯ããããªããŒããããŸã â ãµãŒãã¹åèµ·åã¯äžèŠã§ãã
äžæçãªèªåæå¹æéåãã¯ã©ã€ã¢ã³ãã远å ïŒ
sudo bash /root/awg/manage_amneziawg.sh add guest --expires=7d
cronãžã§ãã¯5åããšã«ãã§ãã¯ããæå¹æéãåãããšãã«ã¯ã©ã€ã¢ã³ããèªåçã«åé€ããŸããèšå®ãããŒããµãŒããŒãšã³ããªã¯ãã¹ãŠã¯ãªãŒã³ã¢ãããããŸãã
ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãããªã¹ãïŒ
sudo bash /root/awg/manage_amneziawg.sh list
Clients: my_phone (10.9.9.2/32) my_laptop (10.9.9.3/32) my_desktop (10.9.9.4/32) guest (10.9.9.5/32) [expires in 6d 23h]
å ¬ééµãšäœææ¥ãå«ã远å ã®è©³çްã«ã€ããŠã¯ã-vãã©ã°ã远å ããŸãã
ã¯ã©ã€ã¢ã³ããåé€ïŒ
sudo bash /root/awg/manage_amneziawg.sh remove guest
å®å šãªãµãŒããŒã¹ããŒã¿ã¹ããã§ãã¯ïŒ
sudo bash /root/awg/manage_amneziawg.sh check
ããã¯ããµãŒãã¹ç¶æ ãéããŠããããŒãããã¹ãŠã®AWG 2.0ãã©ã¡ãŒã¿ãã«ãŒãã«ã¢ãžã¥ãŒã«ç¶æ ãUFWç¶æ ãFail2Banç¶æ ã1ã€ã®ãã¥ãŒã§è¡šç€ºããŸãã
ã¯ã©ã€ã¢ã³ãããšã®ãã©ãã£ãã¯çµ±èšã衚瀺ïŒ
sudo bash /root/awg/manage_amneziawg.sh stats
Client Received Sent Latest handshake âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ my_phone 1.24 GiB 356.7 MiB 2 minutes ago my_laptop 892.3 MiB 128.4 MiB 15 seconds ago my_desktop 0 B 0 B (none)
ããã¯ã¢ãããäœæïŒ
sudo bash /root/awg/manage_amneziawg.sh backup
ããã¯/root/awg/backups/ã«å§çž®ã¢ãŒã«ã€ããäœæãããµãŒããŒèšå®ãã¯ã©ã€ã¢ã³ãèšå®ãããŒãæå¹æéããŒã¿ãå«ãŸããŸãã
ð æ³šïŒaddããã³removeã³ãã³ãã¯ããããªããŒãçšã«awg syncconfã䜿çšããŸãããµãŒããŒèšå®ã¯ãµãŒãã¹ãåèµ·åããããšãªãå³åº§ã«æŽæ°ãããŸããããŒããMTUãªã©ã®ãµãŒããŒåŽãã©ã¡ãŒã¿ã倿Žããå Žåã®ã¿restartã䜿çšããŠãã ããã
6.5 â ãµãŒããŒãå®è¡äžã§ããããšã確èª
ãããã®ãã§ãã¯ãå®è¡ããŠããã¹ãŠãæ£åžžã«åäœããŠããããšã確èªããŸãïŒ
systemdãµãŒãã¹ããã§ãã¯ïŒ
sudo systemctl status awg-quick@awg0
â awg-quick@awg0.service - AmneziaWG Quick via awg-quick(8) for awg0
Loaded: loaded (/lib/systemd/system/awg-quick@.service; enabled)
Active: active (exited) since Thu 2026-04-09 14:32:01 UTCAmneziaWGã¹ããŒã¿ã¹ãšãã©ã¡ãŒã¿ã確èªïŒ
sudo awg show awg0
ãã¡ã€ã¢ãŠã©ãŒã«ã確èªïŒ
sudo ufw status verbose
Status: active Default: deny (incoming), allow (outgoing) 22/tcp LIMIT IN Anywhere 39743/udp ALLOW IN Anywhere
Fail2Banã確èªïŒ
sudo fail2ban-client status sshd
Status for the jail: sshd |- Filter | |- Currently failed: 0 | `- Total failed: 0 `- Actions |- Currently banned: 0 `- Banned IP list:
DKMSã«ãŒãã«ã¢ãžã¥ãŒã«ã確èªïŒ
dkms status
amneziawg/1.0.0, 6.8.0-110-generic, x86_64: installed
5ã€ã®ãã§ãã¯ããã¹ãŠãã¹ããå ŽåãAmneziaWG 2.0ãµãŒããŒã¯å®è¡äžã§æ¥ç¶ãåãå ¥ããæºåãã§ããŠããŸãã
ãµãŒããŒã¯å®è¡äžã§æ€èšŒãããŠããŸããã¿ãŒããã«ã®ä»£ããã«GUIããªãã³ã¢ãããŒããåžæããå Žåã¯ãAmneziaVPNã¢ããªã䜿çšããå¥ã®æ¹æ³ããããŸãã
æ¹æ³2 â AmneziaVPNã¢ããªã§ãããã€ïŒä»£æ¿æ¹æ³ïŒ
AmneziaVPNãã¹ã¯ãããã¢ããªã±ãŒã·ã§ã³ã¯ãSSHãçµç±ããŠãµãŒããŒäžã«AmneziaWGãèªåã€ã³ã¹ããŒã«ã§ããŸããCLIã¡ãœãããšåãåºç€ãšãªãã€ã³ã¹ããŒã©ãŒã¹ã¯ãªããã䜿çšããŠããŸããããã¹ãŠãã¬ã€ãä»ãã€ã³ã¿ãŒãã§ãŒã¹ã§ã©ããããŠããŸãããã³ãºãªããªã€ã³ã¹ããŒã«äœéšãåžæããå Žåã«æé©ã§ãã
- AmneziaVPNãamnezia.org/en/downloadsããããŠã³ããŒãããŸããWindowsãmacOSãLinuxãAndroidãiOSã§å©çšå¯èœã§ãã
- ã¢ããªãéããâïŒãã©ã¹ã¢ã€ã³ã³ïŒãŸãã¯ãGet Startedããã¯ãªãã¯ããŸãã
- æç€ºããããªãã·ã§ã³ãããSelf-hosted VPNããéžæããŸãã
- ãµãŒããŒèªèšŒæ
å ±ãå
¥åããŸãïŒ
- ãµãŒããŒIPã¢ãã¬ã¹ïŒSSHãããŒã22ã§ãªãå Žåã¯ããŒããå«ãããäŸïŒ203.0.113.10:2221ïŒ
- SSHãŠãŒã¶ãŒåïŒäŸïŒrootïŒ
- ãã¹ã¯ãŒããŸãã¯SSHç§å¯éµ
- ã€ã³ã¹ããŒã«ã¿ã€ããéžæããŸãïŒ
- èªåâ AmneziaWGã®ã¿ãã€ã³ã¹ããŒã«ïŒæšå¥šïŒ
- æåâ ãªã¹ãããç¹å®ã®ãããã³ã«ãéžæ
- ãInstallããã¯ãªãã¯â ã¢ããªã¯SSHçµç±ã§ãµãŒããŒã«æ¥ç¶ããã€ã³ã¹ããŒã«ãèªåçã«å®è¡ããŸãã鲿ã€ã³ãžã±ãŒã¿ãŒã衚瀺ãããŸãã
- ã€ã³ã¹ããŒã«åŸãã¢ããªã¯äœ¿çšå¯èœãªVPNæ¥ç¶ãããã¡ã€ã«ãäœæããŸãã
ã€ã³ã¹ããŒã«åŸã®æ³šæäºé ïŒ
- ã¢ããªã¯ããã©ã«ãã§ã©ã³ãã ããŒãã§AmneziaWGãã€ã³ã¹ããŒã«ããŸããäžéšã®ISPã¯é«ãããŒãã®UDPããããã¯ããŸããã¢ããªã¯9999以äžã®ããŒãïŒäŸïŒ585ãŸãã¯1234ïŒãžã®å€æŽãæšå¥šããŠããŸãã倿Žããã«ã¯ïŒæ¥ç¶ã®æšªã«ããã®ã¢ã¢ã€ã³ã³ãã¯ãªã㯠â ãManagementãã¿ã â ããŒãçªå·ã倿ŽããŸãã
- ãµãŒããŒã«ãã§ã«Amnezia ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããŠããå Žåã¯ãæ¥ç¶äœæäžã«ãSkip setupããã¯ãªãã¯ãããã®åŸãManagementãã¿ãã§ãCheck the server for previously installed Amnezia servicesãã䜿çšããŸãã
2ã€ã®æ¹æ³ã®æ¯èŒã¯ä»¥äžã®éãã§ãïŒ
| é ç® | CLIã€ã³ã¹ããŒã©ãŒ | AmneziaVPNã¢ã㪠|
|---|---|---|
| å¶åŸ¡ | å®å š â ãã¹ãŠã®ã¹ãããã衚瀺ãããã«ã¹ã¿ãã€ãºå¯èœ | éå®ç â ã¢ããªããã¹ãŠãåŠç |
| å¯èŠæ§ | ééç â ãã¹ãŠã®ã³ãã³ãã衚瀺ããã | äžéæ â ããã¯ã°ã©ãŠã³ãã§å®è¡ |
| æè»æ§ | ã«ã¹ã¿ã ã«ãŒãã£ã³ã°ããšã³ããã€ã³ãããã©ã° | ããã©ã«ãèšå®ã®ã¿ãäœ¿çš |
| 䜿ãããã | SSHã®ç¥èãå¿ èŠ | ã¿ãŒããã«äœæ¥ãªã |
| 管ç | å®å šãªmanage_amneziawg.shã¹ã€ãŒã | ã¢ããªããŒã¹ã®ç®¡çã®ã¿ |
| æé©çšé | ã¢ã³ãããŒãžãVPSããã©ãã«ã·ã¥ãŒãã£ã³ã° | è¿ éãªã»ããã¢ãããã¬ã€ãä»ãäœéš |
CLIãŸãã¯ã¢ããªã®ãããã䜿çšããå Žåã§ãããµãŒããŒã¯æºåå®äºã§ããæ¬¡ã¯æåã®ããã€ã¹ãæ¥ç¶ããŸãããã
æåã®ã¯ã©ã€ã¢ã³ããæ¥ç¶ãã
ã€ã³ã¹ããŒã«åŸãAmnezia VPN ã¢ããªã«ã¯ã©ã€ã¢ã³ãèšå®ãã€ã³ããŒããã3ã€ã®æ¹æ³ããããŸããã䜿ãã®ããã€ã¹ã«åã£ãæ¹æ³ãéžæããŠãã ããã
æ¹æ³ A: QR ã³ãŒãïŒã¢ãã€ã«ïŒ
ã€ã³ã¹ããŒã©ãŒã¯ /root/awg/my_phone.png ã« QR ã³ãŒããçæããŸãããã³ã³ãã¥ãŒã¿ãŒã«ããŠã³ããŒãããŸã:
scp root@<SERVER_IP>:/root/awg/my_phone.png .
PNG ãã¡ã€ã«ãã¹ã¯ãªãŒã³ã«è¡šç€ºããŸããã¹ããŒããã©ã³ã§ Amnezia VPN ã¢ããªãéãããVPN ã远å ã â ãQR ã³ãŒããã¹ãã£ã³ã ãã¿ããããŠãã¹ã¯ãªãŒã³ã® QR ã³ãŒãã«ã«ã¡ã©ãåããŸããæ¥ç¶ãèªåçã«ã€ã³ããŒããããŸãã
æ¹æ³ B: vpn:// URIïŒAmnezia ã¯ã©ã€ã¢ã³ãïŒ
ãµãŒããŒã§å§çž® URI ã衚瀺ããŸã:
cat /root/awg/my_phone.vpnuri
vpn://… æååå šäœãã³ããŒããŠãTelegramãã¡ãŒã«ããŸãã¯ã¡ã¢ã¢ããªçµç±ã§èªåèªèº«ã«éä¿¡ããŸããã¹ããŒããã©ã³ã§ Amnezia VPN ã¢ããªãéãããVPN ã远å ã â ãã¯ãªããããŒããã貌ãä»ãã ãã¿ããããŸããèšå®ã1ã¹ãããã§ã€ã³ããŒããããŸãã
URI ã¯ãå®å šãªèšå®ãã¡ã€ã«ã® zlib å§çž®ãBase64 ãšã³ã³ãŒãçã§ããã³ã³ãã¯ãã§ãè¿ éãªå ±æçšã«èšèšãããŠããŸãã
æ¹æ³ C: .conf ãã¡ã€ã«ïŒãã¹ã¯ããã/WindowsïŒ
èšå®ãã¡ã€ã«ãããŠã³ããŒãããŸã:
scp root@<SERVER_IP>:/root/awg/my_phone.conf .
AmneziaWG for Windows ã¯ã©ã€ã¢ã³ããŸã㯠AmneziaVPN ãã¹ã¯ãããã¢ããªãéããããã¡ã€ã«ãããã³ãã«ãã€ã³ããŒãã ãã¯ãªãã¯ããŠã.conf ãã¡ã€ã«ãéžæããŸãã
æ¥ç¶ã確èªãã
æ¥ç¶åŸããã³ãã«ããµãŒããŒçµç±ã§ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ããŠããããšã確èªããŸã:
curl ifconfig.me
åºåã«ã¯ããŒã«ã« IP ã§ã¯ãªãããµãŒããŒã®ãããªã㯠IP ã¢ãã¬ã¹ã衚瀺ãããã¯ãã§ã: 203.0.113.1
詳现æ å ±ïŒãµãŒããŒã®å°ççäœçœ®ãå«ãïŒã«ã€ããŠã¯:
curl -s https://ipinfo.io/json
{
"ip": "203.0.113.1",
"city": "Amsterdam",
"region": "North Holland",
"country": "NL",
...
}â ïž èŠå: æšæº WireGuard ã¯ã©ã€ã¢ã³ã㯠AmneziaWG 2.0 èšå®ã§ã¯ æ©èœããŸãããAmnezia VPN ã¢ããªïŒããŒãžã§ã³ 4.8.12.7 以éïŒãŸãã¯ãã€ãã£ã AmneziaWG ã¯ã©ã€ã¢ã³ãïŒWindows/Android/iOS ã§ããŒãžã§ã³ 2.0.0 以éïŒã䜿çšããå¿ èŠããããŸãã
â ïž èŠå: Windows ã§ ãInvalid key: s3ã ã衚瀺ãããå ŽåãAmneziaWG Windows ã¯ã©ã€ã¢ã³ããå€ãïŒããŒãžã§ã³ 2.0.0 æªæºïŒã§ããããŒãžã§ã³ 2.0.0 以éã«æŽæ°ããããAmnezia VPN ã¢ããªã«åãæ¿ããŠãã ããã
ð¡ ãã³ã: æ¥ç¶ãããŠãããã€ã³ã¿ãŒãããããªãå Žåã¯ãã¯ã©ã€ã¢ã³ãèšå®ã® [Interface] ã»ã¯ã·ã§ã³ã« MTU = 1280 ãããããšã確èªããŠãã ãããããã¯ã¢ãã€ã«ãããã¯ãŒã¯ã§ããã³ãã·ã§ã€ã¯ã¯æåãããã
次ã®ã¹ããã â ã»ããã¢ããã®æ¡åŒµ
ããã§ãèªåã®ãµãŒããŒäžã§ãèªåã®ç®¡çäžã§ãWireGuard䞊ã¿ã®é床ãåããDPIèæ§VPNãã³ãã«ã皌åããŠããŸããWireGuardæ¥ç¶ã殺ããŠãããµã€ã¬ã³ããã±ãããã¹ã¯ãã¯ãåé¡ã§ã¯ãªãããã©ãã£ãã¯ã¯DPIã·ã¹ãã ã確å®ã«èå¥ã§ããªã圢ã«èŠããŸãã
次ã«å®è¡ã§ããæãæçšãªããšã¯ä»¥äžã®éãã§ãïŒ
- ãã¡ããªãŒãŸãã¯ããŒã ã®ã¯ã©ã€ã¢ã³ãã远å ãã â 管çã¹ã¯ãªããã䜿çšããŠãã¢ã¯ã»ã¹ãå¿ èŠãªãã¹ãŠã®ããã€ã¹ã®èšå®ãçæããŸãã
- ã¹ããªãããã³ããªã³ã°ãèšå®ãããã«ãã³ãã«ã«ãŒãã£ã³ã°ãäžèŠãªå Žå â ããŒã«ã«ãã©ãã£ãã¯ãé«éã«ä¿ã¡ãVPSäžã®åž¯åå¹ ãåæžããŸãã
- èšå®ãããã¯ã¢ãããã â ããã¯ã¢ããã³ãã³ããå®è¡ããã¢ãŒã«ã€ããå®å šãªå Žæã«ä¿åããŸãããµãŒããŒãåæ§ç¯ããå¿ èŠãããå ŽåãããããŒãããããçŽãããšããæããŸãã
ã¹ããªãããã³ããªã³ã°ãèšå®ãããã¹ãŠã®ãã©ãã£ãã¯ãVPNçµç±ã§ã«ãŒãã£ã³ã°ããå¿ èŠããªãå Žåãããã¯éšåçãªæ€é²ãããåœã§ç¹ã«æçšã§ã â ãããã¯ããããµã€ãã®ã¿ããã³ãã«çµç±ã§ã«ãŒãã£ã³ã°ããããŒã«ã«ãã©ãã£ãã¯ã¯çŽæ¥æ¥ç¶ã®ãŸãŸã«ããŸãïŒ
sudo bash /root/awg/manage_amneziawg.sh modify my_phone AllowedIPs "192.168.1.0/24,10.0.0.0/8"ã¯ã©ã€ã¢ã³ãDNSã倿Žããç°ãªããªãŸã«ããŒãåªå ããå ŽåïŒ
sudo bash /root/awg/manage_amneziawg.sh modify my_phone DNS "8.8.8.8,1.0.0.1"PersistentKeepaliveã調æŽããã¢ã°ã¬ãã·ããªNATèšå®ã䜿çšããŠããå Žåãããã©ã«ãã®33ç§ã¯NATãéããŠUDPã»ãã·ã§ã³ãç¶æããŸã â 25ã«äœäžããããšãã¢ã€ãã«UDPã»ãã·ã§ã³ãçŽ æ©ããããããããããã¯ãŒã¯ã§åœ¹ç«ã¡ãŸãïŒ
sudo bash /root/awg/manage_amneziawg.sh modify my_phone PersistentKeepalive 25ã«ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããããã¯ãŒã¯å šäœã®ã«ãã¬ããžã®ãããAmneziaWGã¯Keeneticã«ãŒã¿ãŒäžã§AWG Managerçµç±ã§ãµããŒããããAsuswrt-Merlinãå®è¡ããŠããASUSã«ãŒã¿ãŒäžã§AmneziaWG for Merlinçµç±ã§ãµããŒããããŠããŸãã
èšå®ãããã¯ã¢ããããä»ãããäœãå€ããåã«ïŒ
sudo bash /root/awg/manage_amneziawg.sh backupæ°ãããµãŒããŒã«ç§»è¡ããå¿ èŠãããå Žåã¯ãæ°èŠã€ã³ã¹ããŒã«ãå®è¡ããŠããïŒ
sudo bash /root/awg/manage_amneziawg.sh restore
sudo bash /root/awg/manage_amneziawg.sh regenrestoreã³ãã³ãã¯èšå®ãšããŒã埩å ããregenã¯ã¯ã©ã€ã¢ã³ãèšå®ãæ°ãããµãŒããŒIPã§æŽæ°ããŸãã
ãã詳ããããã¥ã¡ã³ãã«ã€ããŠã¯ãå ¬åŒAmneziaããã¥ã¡ã³ãã¯docs.amnezia.orgã«ãããã³ãã¥ããã£ã¯Telegramã§æŽ»åããŠããŸãã
çµè«
å®å šãªã»ããã¢ãããéããŠãAmneziaWG 2.0ã®ç¹çãã¹ãç¹ã¯ãåã«æ©èœããã ãã§ã¯ãªããä»ã®ãœãªã¥ãŒã·ã§ã³ã倱æããå Žæã§ç¢ºå®ã«æ©èœããããšã§ããWireGuardã®å®èšŒæžã¿ã®æå·åã³ã¢ãä¿æããªããããããã¯ãŒã¯äžã®ãã©ãã£ãã¯ã®èŠãæ¹ãæ ¹æ¬çã«å€ããããšã§ãDeep Packet Inspectionãæªçšããæ£ç¢ºãªåŒ±ç¹ãåé¿ããŸãããã®çµæãå®éã«ã¯WireGuardãšåããããé«éã§ã·ã³ãã«ã«æããã»ããã¢ããã§ãããæµå¯Ÿçãªç°å¢ã§ã¯ããã«èæ§ããããŸãããããã€ããããšããã®äŸ¡å€ã¯æããã«ãªããŸããåãªãVPNãå®è¡ããŠããã®ã§ã¯ãªããå®äžçã®ããããã³ã°ã«èããããã«æ§ç¯ãããVPNãå®è¡ããŠããã®ã§ãã
AmneziaWGãµãŒããŒããã¹ãããããã®ä¿¡é Œæ§ã®é«ãVPSãæ¢ããŠããããããŒã ã¡ã³ããŒã®è¿œå ãšã³ããã€ã³ãã§ã¹ã±ãŒã«ã¢ããããå¿ èŠãããå ŽåãAvaHostã¯ãã®ã»ããã¢ããã«å¿ èŠãªKVMä»®æ³åããã«root accessãUbuntu 24.04ãµããŒããNVMeã¹ãã¬ãŒãžãæäŸããŸãã圌ãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ããã®ã¬ã€ãã察象ãšããèªå·±ãã¹ãåãããã€ã¡ã³ãã®çš®é¡ã®ããã«ç®çå¥ã«æ§ç¯ãããŠããŸãã