All of AmneziaWG's speed and cryptographic hygiene — with the identity, key management, and auditability your organization actually requires.
~4,000 lines of code. Modern crypto, boringly applied. Connections that set up in milliseconds.
Kernel-speed performance and instant roaming between networks. No multi-second handshake dances.
A codebase small enough to audit in an afternoon — a feature, not a limitation.
Curve25519, ChaCha20, Poly1305, BLAKE2s: conservative, well-reviewed primitives.
Raw AmneziaWG is a building block. OpenVLAN is the enterprise product built on it.
AmneziaWG keys are anonymous. OpenVLAN binds keys to users from your identity provider, with SCIM provisioning and offboarding that actually revokes access.
No manual key exchange over chat. Nodes authenticate once via your IdP; keys rotate automatically, invisible to users.
Point-to-point tunnels are all-or-nothing. OpenVLAN adds a policy layer: who may reach what, per port, per group — as code.
Flow logs, session recording, and configuration history export to your SIEM — SOC 2, ISO 27001, and HIPAA-friendly.
| AmneziaWG alone | OpenVLAN | |
|---|---|---|
| Encryption | AmneziaWG | AmneziaWG |
| Identity | Static keys | SSO/IdP + device identity |
| Access control | None (all-to-all) | ACLs as code, posture-aware |
| NAT traversal | Manual | Automatic, relay fallback |
| Audit logging | — | Flow logs + session recording |
| Deployment | Per-tunnel config files | One login, fleet-wide |