Where Does AmneziaWG Store Its Config?
AmneziaWG servers keep awg0.conf under /etc/amnezia/amneziawg. Keys, firewall, and sysctl files back it up.
Last updated
AmneziaWG extends WireGuard configs with obfuscation sections (Jc junk trains, S1/S2 length randomization, H1-H4 header shifts, I1-I5 signature chains). Server configs conventionally live at /etc/amnezia/amneziawg/awg0.conf, managed by awg-quick style units. Docker images mount that directory from the host for persistence.
The surrounding files matter as much as the conf. Firewall NAT rules, sysctl forwarding, client key backups, and credentials files travel with it; a conf without NAT routes nothing. Easy-web-UIs keep their own state (e.g. ~/.amnezia-wg-easy) on top of the same conf format. Rotate keys and obfuscation values per deployment: shared parameters across servers weaken the masking story.
Where AmneziaWG stores this, by platform
/etc/amnezia/amneziawg/awg0.conf
Interface, peers, plus Jc/S/H/I obfuscation blocks. Managed by awg-quick@awg0 units. Pair with iptables NAT, sysctl forwarding, and key backups; conf alone routes nothing.
Frequently asked questions
how do i migrate an amneziawg server
Copy /etc/amnezia/amneziawg/awg0.conf plus client keys, iptables rules, and sysctl drops to the same paths and restart awg-quick@awg0. Regenerate obfuscation params per server rather than cloning them; uniqueness is the DPI defense.
do stock wireguard clients work with amneziawg
Yes, with masking off. AmneziaWG without obfuscation parameters speaks plain WireGuard, so stock clients connect. Enable Jc/S1/H1 masking and only Amnezia clients follow. Mixed fleets run unmasked during migration.
Notice an outdated path? Let us know.