Amnezia Self-hosted users have gained access to the updated AmneziaWG 3.1 protocol, and Amnezia Premium users to 3.0.
To see its benefits, install the Amnezia VPN 5.0.1.5 update.
In this article, we’ll explain what changed in our protocol — the successor to WireGuard — and why.
Why We Updated the Protocol
Back in the early stages of the summer attack, members of the Amnezia VPN technical team realized that the blocking had reached a new level. The initial solution, using VLESS as a fallback, proved short-lived.
Where TMCTTechnical Measures to Counter Threats and DPI systems used to analyze individual packets to assess the legitimacy of traffic, the summer’s events showed that censors now assess the connection as a whole, as a data flow, together with the endpoint. Here are just some of these characteristics:
- packet sizes and sequence,
- inter-packet arrival times,
- handshake patterns,
- keepalive packets,
- traffic volume,
- number of connections,
- recurring statistical patterns.
Given that, changing one or even several parameters isn’t enough — a new approach is needed to obfuscate traffic and make it mimic a legitimate one.
To protect user data and guarantee that the service works under the changed conditions, we rebuilt our own protocol — and thus AmneziaWG 3.1 was born.
What Changed
The updated AmneziaWG 3.1 makes blocking bypassing more effective. What’s more, it’s more resistant to attacks on the protocol itself. To ensure user privacy, we:
- Protected traffic from detection at the handshake stageA handshake is the establishment of a connection between two network elements.
- Expanded the set of parameters for randomizing the pre-shared keyA secret code that allows a connection to be established with an Amnezia VPN server.
- Protected against blocking built on behavioral AI analysis — through obfuscation of metadata and technical values.
How to Install AmneziaWG 3.1
To connect via the updated protocol, first install Amnezia VPN 5.0.1.5 or newer. After that, it all depends on which Amnezia VPN service you use.
For Amnezia Premium and Free
Amnezia Premium and Free users get access to AmneziaWG 3.0 by default. No additional setup is required — just select AmneziaWG from the list of protocols.
For Amnezia Self-hosted
Don’t remove the AmneziaWG 2.0 container until you’re sure the new one under AmneziaWG 3.1 is working normally.
- Create a new server under AmneziaWG 3.1. In some cases, the protocol’s operation depends on the i1 parameter — configure it for your connection.
- Issue updated access keys to everyone who connected to your server.
- If no connection problems come up, remove the AmneziaWG 2.0 container.
Important: update the access keys for all users at once as soon as you remove the AmneziaWG 2.0 container
If you have any further questions, we’ve put together detailed instructions in the project documentation. Or in our communities:






