−53%2 years of NvoVPN at 1.70 €/mo instead of 3.61 €Get the deal
Router

VPN on a Keenetic router: AmneziaWG or WireGuard, a file from your account, 10 minutes

8 min read

Keenetic understands AmneziaWG with its stock firmware: download the file, upload it under "Other connections" and turn on "Use for internet access". KeeneticOS versions, DNS, device policies, and speed by model.

VPN on a Keenetic router: AmneziaWG or WireGuard, a file from your account, 10 minutes

A VPN on a Keenetic router installs with no reflashing and no command line: KeeneticOS understands AmneziaWG "out of the box", and the file from your account uploads straight into the router's web interface. The whole thing takes about ten minutes. After that, every device at home goes through the VPN at once — the TV, a streaming box, guests' phones — and for NvoVPN the router counts as one device. If you are in Russia, take the AmneziaWG file; details in the block below.

  1. Download the file from your account

    Open your account → "Connection" → "Manual". Choose a server, name the device "Router" and click "Create". Download the .conf file for AmneziaWG. Next to it is a plain WireGuard variant — on a Keenetic with KeeneticOS 4.3.4 or later, you do not need it. The file is only created while a plan or trial is active.

  2. Check KeeneticOS and the WireGuard component

    The file from your account is AmneziaWG version 1.0; KeeneticOS has been able to read it from a file since version 4.3.4, so KeeneticOS 5.1 is not required. In the router's web interface, open "Management" → "System settings": update KeeneticOS to the current version, then click "Change component set", find "WireGuard VPN" and tick it. There is no separate "AmneziaWG" entry in the list — it is part of this component.

  3. Upload the file and turn on internet access

    "Internet" → "Other connections" → in the WireGuard section, click "Upload from file" and choose the downloaded .conf. In the connection that opens, tick "Use for internet access", click "Save", and make sure the connection toggle is set to "On". Then open "Internet" → "Connection priorities" and drag WireGuard above the provider's connection — that sends all traffic through the tunnel.

  4. Check that the VPN is working

    From a TV or laptop behind the router, open the "What is my IP" page: it should show the NvoVPN server's address, not your provider's. If you see your own city and provider, see the "If the router will not connect" section below.

Every device at home reaches the internet through the router's tunnel — to NvoVPN that is one device.

AmneziaWG or WireGuard — which file to take?

Your account has both, and Keenetic understands both. Take AmneziaWG: it is WireGuard with traffic obfuscation, and it gets through where plain WireGuard is throttled. The WireGuard variant is only for a router on KeeneticOS below 4.3.4 that cannot be updated — and it only works on networks with no blocks. The difference between the protocols is in "AmneziaWG vs WireGuard: what is the difference".

Are you in Russia? Take AmneziaWG — Keenetic understands it natively

In Russia, providers recognize and cut off plain WireGuard, so the WireGuard variant of the file will not work on a Keenetic. Only AmneziaWG works — and that is the brand's main advantage: Keenetic understands the obfuscation with no reflashing.

Option 1 — the AmneziaWG file from your account

The same path as the four steps above: KeeneticOS 4.3.4 and later picks up the obfuscation parameters from the file on its own. There is nothing extra to turn on.

Open your account

Option 2 — connected, but no traffic gets through

If the router shows the tunnel is up, but sites behind it will not open, message support: we will prepare a configuration with a route for Russia and send you a new file. It uploads the same way — "Upload from file".

Contact support

If the router will not connect: Keenetic pitfalls

  • DNS. Keenetic's WireGuard connection has no DNS field, the DNS = line from the file is not applied, and site-name lookups go to the provider, bypassing the tunnel. Set the DNS separately: "Network rules" → "Internet filters" → the "DNS settings" tab → "Add server" — enter the address from your file's DNS line, or a public one (8.8.8.8, 1.1.1.1). In the same place, under "IPv4 parameters", tick "Ignore the ISP's DNSv4".
  • The tunnel is up, but there is no internet. Check the "Use for internet access" tickbox and the order in "Connection priorities": the connection with the highest priority becomes the default gateway, and WireGuard needs to be above the provider.
  • An "invalid H1 value" error when uploading the file. The firmware does not understand the obfuscation parameters in the file. Update KeeneticOS to the current version and upload the file again.
  • The connection keeps dropping. Keenetic recommends a client Persistent keepalive interval of 10–15 seconds instead of the standard 30 — the value is set in the peer settings inside the connection.
  • One file, one device. You cannot use the router's configuration on a phone at the same time: the connection will drop on both. Create a separate one for the phone — a subscription covers up to five.
  • Only some devices need the VPN. "Internet" → "Connection priorities" → "Add policy" → name it → "Save" → in the policy, mark WireGuard first → "Save" → the "Policy assignment" tab → drag devices or network segments into the policy → "Confirm". Up to 16 policies.
  • A kill switch (blocking internet access if the tunnel drops) is not in every router's firmware. If this matters to you, check for the option in your model's VPN client settings, or turn it on on the devices themselves — how to do that.

Keenetic models and firmware

Per the manufacturer's data as of September 2026; the current release is KeeneticOS 5.1.6 from September 16, 2026. Before buying, check your model on its Keenetic downloads page.

  • KeeneticOS 5.1 (the current branch) goes to Giga (KN-1010), Hero (KN-1011, KN-1012), Ultra and Titan (KN-1810–1812), Viva and Skipper (KN-1910, KN-1912, KN-1913), Starter (KN-1112, KN-1121), Air and Explorer (KN-1613, KN-1621), Extra and Carrier (KN-1713, KN-1714, KN-1721), Speedster, Hopper, Sprinter, Challenger, Racer, Peak, Giant, Buddy, Voyager Pro, Orbiter, and the 4G and DSL models (except Runner 4G KN-2210). The NvoVPN file uploads from a file.
  • Stopped at KeeneticOS 4.3: Start (KN-1110, KN-1111), Omni (KN-1410), City (KN-1510), Air (KN-1610), Extra (KN-1710, KN-1711), Runner 4G (KN-2210), Speedster (KN-3010). Update these to 4.3.4 or later — they also load the NvoVPN file (AmneziaWG 1.0) from a file. AmneziaWG 1.5 and 2.0 files from other services (with S3, S4, I1 parameters) do not work on them.
  • Lite (KN-1310) stopped at KeeneticOS 4.2: the obfuscation parameters are entered manually through "Management" → "System settings" → "Command line", following the Amnezia guide for older KeeneticOS versions, or you take the WireGuard variant — where VPNs are not throttled.
  • Netcraze runs on the same KeeneticOS — the steps are the same.
  • AmneziaWG 3.1 is not natively supported by KeeneticOS. This does not affect the NvoVPN file: it is version 1.0.

Official WireGuard throughput from the model pages on keenetic.com:

ModelsWireGuard, up to
Starter KN-1112/1121, Explorer KN-1613/1621, Carrier KN-1711/1713/1721, Runner 4G KN-221245 Mbps
Skipper KN-1912, Speedster KN-3012, Hopper KN-3810, Sprinter KN-3710130 Mbps
Skipper KN-1910/1913, Speedster KN-3010/3013, Hero KN-1011, Titan KN-1810, Hero 4G+ KN-2311180 Mbps
Titan KN-1811440 Mbps
Hero KN-1012, Hopper KN-3811, Sprinter KN-3711, Challenger KN-3910, Racer KN-4010460 Mbps
Titan KN-1812900 Mbps

FAQ

Do I need KeeneticOS 5.1 for AmneziaWG? Not for the NvoVPN file — it is version 1.0, and KeeneticOS has read it from a file since 4.3.4. Version 5.1 is needed for AmneziaWG 1.5 and 2.0 files with S3, S4 and I1 parameters — on KeeneticOS 5.0.8 and earlier, those files produce an "invalid H1 value" error.

Can I route only the TV through the VPN? Yes — create a policy in "Connection priorities" and drag the TV into it on the "Policy assignment" tab (steps are in the pitfalls section above). The other devices will keep going out directly.

Why is the speed through the router lower than my plan? The router's CPU computes the encryption, and it becomes the bottleneck: entry-level Keenetic models officially give up to 45 Mbps through WireGuard, the higher-end ones hundreds. Even the entry-level models are enough for a TV and everyday use.

Can I put the same file on a phone? No — one file only works on one device at a time. Create a separate configuration for the phone in your account, or install the NvoVPN app: a subscription covers up to five devices, and the router is one of them.

Can I skip updating KeeneticOS? On KeeneticOS 4.2–4.3.3, the file uploads without the obfuscation parameters — they are entered manually through "Command line" following the Amnezia guide (linked in the models section). It is simpler and more reliable to update the firmware: from 4.3.4 on, everything comes from the file.

Related guides: How to set up a VPN on a router: an overview by firmware · AmneziaWG vs WireGuard: what is the difference · VPN on an ASUS router · VPN on a TP-Link or Mercusys router · VPN when your provider gave you the router

Did not work?Message support: tell us your device and the step you got stuck on — we will help.
Contact support
Works where VPNs are blocked

Ready to connect?

Download the app and sign in — you are protected. The free trial starts by itself, no card needed.