Support AmneziaWG

Started by Lucid1010, August 05, 2025, 02:50:51 PM

Previous topic - Next topic
May 17, 2026, 07:02:54 PM #30 Last Edit: May 17, 2026, 07:04:44 PM by smoore
There is a legitimate need for a VPN that can work around enterprise SWG. I wrote my story here: https://forum.opnsense.org/index.php?msg=267146

It's also been mentioned that many hotels and other sites that hosts normal civilians impose restrictive policies that truly threaten legitimate work. I've stayed in hotel chains that WG doesn't work so I've used OpenVPN/tls-crypt on 443 to get to my console, but this workaround has aged and easy to catch.

AmneziaWG is one such solution (if the SWG doesn't blanket-kill UDP), but I agree, universal tools like wstunnel are longer-term solutions.

As previously mentioned we're going to put the foot down here and now officially say no to inclusion.


Cheers,
Franco

AmneziaWG 3.1 for OPNsense 26.7 — Public Beta, Testers Wanted

A community beta of os-amneziawg has been published, adding AmneziaWG 3.1 support for OPNsense 26.7 / FreeBSD 15.x amd64.

The runtime uses the amneziawg-go userspace backend, so no AWG kernel module is required. The project includes native FreeBSD/OPNsense packages, AWG 3.1 config import/export, safe Apply with rollback, selective routing through standard OPNsense Aliases/Gateways/Firewall Rules, TUN/UAPI watchdog checks, SHA-256 release verification, and pinned upstream source versions.

Beta1 is built and tested on FreeBSD 15.1 through GitHub Actions. It has also been migrated on a real OPNsense system from an earlier RC installation to the native beta1 packages; the tunnel and selective routing came back up successfully and are working.

The project is still marked as beta because independent testing on different hardware, WAN configurations, and virtualization platforms is needed.

If you test it, I would really appreciate a report including:

* OPNsense and FreeBSD versions
* WAN type: DHCP / PPPoE / static
* fresh installation or migration
* handshake and bidirectional traffic status
* whether selected destinations go through AWG
* whether non-selected traffic still uses the normal WAN
* behavior after reboot
* approximate throughput/speed

There is also an offline installation method for networks where OPNsense fetch cannot reach GitHub because of regional or ISP restrictions, as well as documented safe recovery and uninstall procedures.

This project is not an official component of OPNsense or Amnezia. A significant part of the AWG 3.1 integration, hardening, testing, and documentation was developed and reviewed with the assistance of generative AI. This is disclosed openly in the repository.

Repository:
https://github.com/sergeyvasilev2363-ai/os-amneziawg

Beta release:
https://github.com/sergeyvasilev2363-ai/os-amneziawg/releases/tag/v3.1.2-beta1

Feedback, testing results, bug reports, and code review are very welcome.

@ViRtI6587 I have removed your accidental double-post on the other topic.

Getting a 404 error on your links
Deciso DEC850v2