A VPN on a Keenetic router puts the whole home through one tunnel, with no app on each device. The stock firmware knows WireGuard and AmneziaWG parameters, but not every AmneziaWG version fits our file. Below: which firmware you need as of 2 October 2026, how to load the file, and what we did not test.
In short. Our file needs AmneziaWG 3 with header protection. The main KeeneticOS 5.1.6 firmware (24 September 2026) knows only AmneziaWG 2.0 — our file does not fit it. In the developer channel, KeeneticOS 5.2 Alpha 11 (25 September), Keenetic reports support for version 3.1 parameters: per the description the file should load with a normal import, but we have not tested it on a live Keenetic, and Keenetic does not officially support test builds. A third path is Entware with awg-manager, which we have not tested either.
We make Mayak. The AmneziaWG file for a router is issued in your account page, a router takes one slot on the plan, and for phones and Android TV we have our own app. 3 days free on two devices after you confirm your email, no card needed. The trial is free and needs no card; without an email it is 1 day.
🍎 On iPhone, Mayak works through the subscription link from your account page. The real Happ (publisher Flyfrog LLC) is not in the Russian App Store — searching that word there brings up look-alike apps from other publishers. INCY (publisher LLC ITDEV) works instead: checked on 22 September 2026.
Why the AmneziaWG version matters, not the model
Out of the box Keenetic connects to WireGuard, OpenVPN, IPsec, IKEv2, L2TP/IPsec, SSTP, PPTP and OpenConnect (Keenetic help). AmneziaWG is WireGuard with masking, and Keenetic calls its parameters “ASC”. The masking comes in versions:
- AmneziaWG 1.x and 2.0 — the Jc, Jmin, Jmax, S1–S4, H1–H4, I1–I5 parameters. KeeneticOS accepts them on file import since 5.1.1 (release notes).
- AmneziaWG 3 adds header protection — in the file it is the
HeaderProtectionKeyline. All our lines use it.
Header protection only works paired with the server. Firmware that does not know it will either reject our file or fail to connect, and you cannot delete the line from the file: without it the server will not recognise the router. We keep no lines on the old version — the masking there is weaker.
Which KeeneticOS fits: a version table
| Firmware | What it has of AmneziaWG | Our file |
|---|---|---|
| KeeneticOS 4.2 – 5.0 | first-version parameters (Jc…H4); the notes mention them only for the command line | no |
| KeeneticOS 5.1.1 – 5.1.6, main channel |
AmneziaWG 2.0 on file import; not a word about header protection in the notes | no |
| KeeneticOS 5.2 Alpha 11+, developer channel |
“ASC version 3.1 parameters” (Keenetic notes) | per the description yes, we have not tested |
| Any + Entware and awg-manager |
AmneziaWG 3.0 per the awg-manager changelog | per the description yes, we have not tested |
How to find your version: in the router's web interface, on the start page (the system dashboard), in the “About system” block. Version 5.1.x — our file will not fit yet. When AmneziaWG 3 reaches the main channel, it will be in the release notes: look for “ASC version 3.1” or “AmneziaWG 3”.
The developer channel: how to switch and what it risks
Keenetic itself describes the test build as “in development” and possibly containing bugs, and says official technical support covers only software from the main and preview channels; test builds are discussed on the forum (Keenetic help, in Russian). The router is the whole home's internet, so decide for yourself whether it is worth it.
If you decide to, per Keenetic's help:
- Save backups: the settings file
startup-configand the firmware filefirmware. With them you can go back. - On the general system settings page, choose the developer channel in the update channel field and confirm.
- Update KeeneticOS. The router will reboot; do not switch it off until the update is over.
- In “About system” on the dashboard, check that the version is 5.2 Alpha 11 or newer.
The notes we rely on are published for the Titan model (KN-1810). Whether the same build is out for your model, check the release notes on its support page.
How to load our file into Keenetic
The steps follow Keenetic's WireGuard help. We have not walked them on a Keenetic ourselves.
- Install the WireGuard VPN component. On the general system settings page, in the KeeneticOS update and components section, change the component set and tick WireGuard VPN. After that a WireGuard section appears on the Other connections page.
- Get the file in your account page: the “File for Linux” card → country → “Get the file for Linux” → “Download .conf”. The card says “for Linux”, but it is the same file a router needs. A new file for the same country disables the previous one, and the same file cannot be downloaded twice: the key is not stored on the server. The file holds a secret key — keep it like a password.
- Other connections → WireGuard → Import from a file, and point to the downloaded file.
- Check that it connects. Open the connection check from a computer behind the router: the address should be our server's address in the country you chose. How to send the whole home or only some devices through the tunnel is in Keenetic's help; we have not tested those settings.
Import failed or no connection on 5.2 Alpha 11 or newer — write to us with the firmware version and the error text, without the file itself: we will sort it out and add it here.
Keenetic with Entware: awg-manager
Entware is third-party packages for Keenetic. They need the open-packages (OPKG) support component and a USB drive with an EXT file system (Keenetic recommends EXT4); on some models since KeeneticOS 3.7 the packages can go to internal memory (Keenetic help, in Russian). Keenetic support does not advise on external packages.
Among the packages is awg-manager, an independent open-source project. Per its changelog, it has supported AmneziaWG 3.0 with header protection since 2.16.4 (31 July 2026), and since 2.17.4 adds it with its own module even on firmware that does not know it. So our file should suit it. The latest release as of 2 October is 2.19.12 of 29 September. We have not tested it: Keenetic cannot run in a virtual machine, and we have no live router.
If you would rather not change firmware
- Wait for the main channel. Keenetic itself calls the developer channel what it is “working on right now”; it does not say when that reaches the main channel, and we will not guess.
- Put Mayak on the devices themselves. An Android phone and an Android TV — with our app; a computer — per the computer guide; a Samsung or LG TV — through an Android TV box. Each device then takes its own plan slot.
- A router on OpenWrt. We tested our file on OpenWrt 24.10.8 with the awg-openwrt package (in a virtual machine): seven steps.
How many plan slots a router takes
One, like a phone. A file is issued for one country: another country means another file and one more slot. As of 2 October 2026, “Start” covers up to 3 devices for 300 ₽ a month, “Family” up to 5 for 500 ₽, “Max” up to 10 for 700 ₽. The trial covers two devices: a phone and a router both fit.
Mind the end of access. The router sends the whole home into the tunnel, so when access ends or the router is removed from Devices, everyone loses the internet. That is what happened in our OpenWrt test (details); on Keenetic we have not tested it, but the server behaves the same. Renew in advance, or turn off the WireGuard connection on the Other connections page.
A router in Mayak is just one more device on the same account. Sign up, get the file in your account page and load it into a router with suitable firmware. We ask for no payment details for the trial. A confirmed email opens the access — 3 free days. An email is optional: without one the trial is 1 day.
What we tested
- KeeneticOS release notes — the main channel up to 5.1.6 and the developer channel up to 5.2 Alpha 11, opened on 2 October 2026 (links in the text). The “ASC version 3.1” line is quoted from Keenetic's notes verbatim.
- Keenetic help on WireGuard, the developer channel and Entware — also on 2 October.
- The awg-manager changelog on GitHub — on 2 October.
- Our file on OpenWrt — with a live connection in a virtual machine, on 24 September 2026: header protection and the other parameters came through the import, and the connection came up (details). That shows the file suits a router, but says nothing about how Keenetic will parse it.
What we do not know
- Whether KeeneticOS 5.2 Alpha 11 accepts our file. Keenetic writes about “ASC 3.1 parameters”, but its notes do not say “header protection”; that it is included comes from the third-party awg-manager. We have no live Keenetic.
- Which models got 5.2 Alpha 11, and whether Netcraze did too. We looked at the notes for the KN-1810 model.
- When AmneziaWG 3 will reach the main channel. Keenetic gives no dates.
- awg-manager on a live router, speed on Keenetic, behaviour after access ends specifically on Keenetic — not tested.
- Which error 5.1.x shows when importing our file — not tested. Send us your case and we will add it.
Short answers
How do I set up a VPN on a Keenetic router? Install the WireGuard VPN component and import the file on the Other connections page. Our file needs firmware with AmneziaWG 3 for this: as of 2 October 2026 that is only the developer channel, 5.2 Alpha 11 and newer, and we have not tested it.
Does Keenetic support AmneziaWG? Yes: version 2.0 on file import since 5.1.1; version 3.1 parameters in the developer channel since 5.2 Alpha 11.
Can I set up a VPN on Keenetic without a USB drive? With the stock WireGuard, yes: no drive needed. A drive is needed for Entware, and not on every model.
Can your file be converted to AmneziaWG 2.0? No: without the header protection line our server will not recognise the router.
What about Netcraze? We have not opened their release notes. Look there for the same words: “ASC version 3.1” or “AmneziaWG 3”.
How much is it? A router is one plan slot: “Start” is up to 3 devices for 300 ₽ a month. The trial needs no card and covers two devices.