Protocol guide

AmneziaWG vs WireGuard: how AmneziaWG hides the WireGuard fingerprint

AmneziaWG is WireGuard with a disguised handshake. It sends junk packets before connecting (Jc, Jmin, Jmax), pads handshake messages with random bytes (S1, S2) and replaces WireGuard's fixed message-type values (H1–H4). The standard WireGuard signature disappears, while the encryption and most of the speed stay the same. On unfiltered networks, plain WireGuard is still fine.

DXVPN teamUpdated 5 min read

Key points

  • Plain WireGuard is fast but easy for DPI to recognise.
  • AmneziaWG keeps WireGuard's cryptography and changes how packets look.
  • The cost is small overhead and the need for an AmneziaWG client.
  • AmneziaWG is the protocol DXVPN uses on MikroTik routers.

The short answer

AmneziaWG is a fork of WireGuard that changes what the traffic looks like, not how it is encrypted. It is designed to remove the patterns DPI uses to recognise WireGuard, at a small cost in overhead.

WireGuard is a widely respected VPN protocol: small, fast and well reviewed. Its weakness on censored networks is that it was never meant to hide. AmneziaWG fills that gap. It is one of DXVPN's 7 protocols. Our site rates it 4 out of 5 for DPI resistance, and it is usually the fastest option we offer.

Why plain WireGuard is easy to spot

WireGuard's packets have a fixed, well-documented shape. A DPI system can recognise a WireGuard handshake within the first couple of packets.

Three things give it away:

  • Fixed message types. Every WireGuard packet starts with a type value: 1 for handshake initiation, 2 for the response, 3 for a cookie reply and 4 for data. These bytes never change.
  • Fixed handshake sizes. The initiation message is always 148 bytes and the response always 92 bytes.
  • A predictable start. The client sends the initiation, the server answers, and data flows. There is nothing in between.

This makes WireGuard easy to fingerprint, which is why DXVPN rates plain WireGuard 1 out of 5 for DPI resistance. Read more about how this works in what deep packet inspection is.

How AmneziaWG hides the fingerprint

AmneziaWG changes each of those tell-tale features with a small set of parameters. Client and server agree on the values, so to an observer the packets no longer match WireGuard's known pattern.

ParameterWhat it doesWhat it hides
JcNumber of junk packets sent before the handshakeThe predictable "initiation first" start
Jmin, JmaxMinimum and maximum size of those junk packetsUniform sizes at the start of a session
S1Random bytes added to the handshake initiationThe fixed 148-byte initiation size
S2Random bytes added to the handshake responseThe fixed 92-byte response size
H1–H4Custom values that replace message types 1–4The fixed type bytes at the start of every packet

With these in place, the first packets of a session have random content and varied sizes, and the headers no longer carry WireGuard's known values. The key exchange and data encryption underneath are unchanged: ChaCha20-Poly1305, as in WireGuard.

WireGuard

Packet 1: type 1, 148 bytes. Packet 2: type 2, 92 bytes. Then type 4 data packets.

AmneziaWG

Several junk packets of random size, then a padded initiation and a padded response with custom header values, then data with custom headers.

The encryption is the same. Only the outside shape of the packets changes.

What it costs

The trade-offs are modest, but they are real. Here is what you give up compared with plain WireGuard.

  • A little overhead. Junk packets and padding add some bytes to each handshake. Data packets after the handshake stay close to WireGuard's size, so everyday speed is barely affected.
  • A compatible client. Standard WireGuard apps cannot talk to an obfuscated AmneziaWG server. You need an app that supports AmneziaWG.
  • Still UDP. AmneziaWG runs over UDP like WireGuard. If a network blocks or degrades UDP broadly, a TCP-based protocol such as VLESS + Reality may work better.
  • Not the strongest disguise. AmneziaWG removes WireGuard's signature, but it does not imitate a real website the way Reality does. That is why it scores 4 rather than 5.

When plain WireGuard is fine

If your network does not filter VPNs, plain WireGuard is a perfectly good choice. The obfuscation only pays off where DPI is looking for it.

Typical examples are home broadband, office networks and travel in countries that do not restrict VPN use. There, WireGuard's simplicity and wide support in routers and operating systems are real advantages. Switch to AmneziaWG when WireGuard connects and then drops, never completes the handshake, or becomes unusably slow on a particular network.

DXVPN's current plans do not include plain WireGuard. We offer AmneziaWG instead, because our service is built for networks with DPI-based censorship.

AmneziaWG at DXVPN

At DXVPN, AmneziaWG is the pick for speed, for phones and for routers. It is currently served by both of our online nodes, including the one in the Netherlands.

  • Russia: it is our second recommendation after VLESS + Reality, ahead of Trojan.
  • Routers: a MikroTik router on RouterOS 7.x with container support can run an AmneziaWG container, covering the whole home network. This requires the Family plan. See VPN on a MikroTik router.
  • Plans: AmneziaWG is included on Free, Pro, Family and Business. Basic includes VLESS, Trojan and Shadowsocks only.

If AmneziaWG gets blocked on your network, switch to VLESS + Reality or Trojan in the same app. Our protocol comparison helps you choose, and the protocols section gives a one-screen overview.

Getting started

Setting up AmneziaWG takes a few minutes. Create an account, get your config and import it into a compatible app.

  1. Sign up on the registration page or via @dxvpnbot. The Free plan needs no card.
  2. Get your config as a subscription link, a file or a QR code from the dashboard or the bot.
  3. Import it into an AmneziaWG-compatible app and connect.

For a wider look at app options, visit the download page.

Questions

Is AmneziaWG as secure as WireGuard?

AmneziaWG keeps WireGuard's cryptography, including ChaCha20-Poly1305. The changes affect how packets look on the wire, not how the data is encrypted.

Can I connect to an AmneziaWG server with a normal WireGuard app?

Usually not, once obfuscation is switched on. The headers and padding no longer match what standard WireGuard expects, so you need an AmneziaWG-compatible client.

Is AmneziaWG slower than WireGuard?

Slightly, in theory: it sends a few extra junk packets and bytes during the handshake. Data packets after the handshake stay lean, so the difference in everyday use is small.

When is plain WireGuard good enough?

On networks without DPI-based filtering, such as most home and office connections in countries that do not block VPNs. Where WireGuard gets blocked or throttled, AmneziaWG is the better choice.

Sources

  1. Amnezia documentation
  2. amnezia-vpn/amneziawg-go on GitHub
  3. WireGuard
  4. WireGuard protocol overview

General information, not legal advice. VPN rules differ by country — check the law where you are.

See it for yourself

Run the “what the censor sees” check on the home page, or start on the free plan — no card needed.

Read next