Paste an AmneziaWG .conf (1.0 through 3.0) to generate ready-to-use MikroTik RouterOS commands
AmneziaWG Configuration File
All configuration and data is processed locally in your browser. Nothing is transmitted anywhere. Your private keys are safe.
WireGuard client on MikroTik + awg-proxy runs inside a Docker container directly on the router
Routes traffic to selected services through the tunnel using DNS forwarding (DoH). ⓘ
FastTrack rules will be modified (out-interface-list=WAN) to keep FastTrack active for non-VPN traffic. Uninstall script restores them.
All services will use this DNS-over-HTTPS (DoH) provider for domain resolution.
Monitors tunnel availability by pinging 8.8.8.8 through the WG interface (via a pinned probe route). If the tunnel is down, disables its route — traffic falls back to the next tunnel (by distance) or goes direct. Re-enables the route when the tunnel recovers.
Adds AWG_NO_DF=1 to the container ENV: the proxy clears the Don’t Fragment bit on its UDP packets. Some DPI equipment passes DF=0 UDP better than DF=1. Enable only if the tunnel has connectivity issues — with DF=0 large packets may be fragmented along the path.
The IPv6 header is 40 bytes instead of 20, so a full-size packet no longer fits a 1500-byte path and the WireGuard MTU has to come down. Ticked automatically when the endpoint is an IPv6 literal. For a DNS name the box stays off (IPv4 MTU) — tick it yourself if you know the name has an AAAA record; the generated script also asks the router with :resolve type=ipv6 and lowers the MTU if it answers.
Change the prefix only if you need 2+ tunnels with different routing rules
Both sides are generated by this page, so the newest level is the safe default. Every side needs an awg-proxy image that understands it.
Adds a fallback chain down to AWG 1.0. A peer still running an older container connects on the stage it understands; costs nothing while everyone is on the same level.
Updating an existing installation A container built before 3.0 does not understand header protection: adding the new variables is not enough. Pull the new image and recreate the container.
Adding a new client to server
Devices will be able to reach each other by IP across subnets. What becomes possible: access NAS/file shares, IP cameras, printers by address, remote desktop (RDP/VNC), manage routers via WinBox/SSH, host game servers, access home automation (Home Assistant). Does NOT work: broadcast/multicast services. Note: each client only sees the server LAN by default. To connect two clients to each other, additional routes must be added manually.
Both sides are generated by this page, so the newest level is the safe default. Every side needs an awg-proxy image that understands it.
Adds a fallback chain down to AWG 1.0. A peer still running an older container connects on the stage it understands; costs nothing while everyone is on the same level.
Updating an existing installation A container built before 3.0 does not understand header protection: adding the new variables is not enough. Pull the new image and recreate the container.
Parsed parameters
MikroTik RouterOS Commands
Step 2: Routing Setup
Paste this AFTER Step 1 completes (wait for "Installation complete!").
Uninstall Commands
Side A (MikroTik 1) — client
Uninstall Side A (client)
Side B (MikroTik 2) — server
Uninstall Side B (server)
⚠️ SAVE THIS LINK FOR FUTURE CONFIGURATION
This link will also be saved in container env AWG_CONFIG_URL. To retrieve it later: /container/envs/print where key=AWG_CONFIG_URL