Skip to content

VPN Monitoring

The Control Center monitors WireGuard VPN tunnels in real-time by parsing the output of wg show all dump.

How It Works

Data Source

The wg show all dump command outputs tab-separated data with two line types:

Interface line (5 fields):

strato-host    <privkey>    <pubkey>    51820    0

Peer line (9 fields):

strato-host    <pubkey>    <psk>    91.7.98.176:54682    10.0.0.2/32    1711975423    1300976    4061948    25

Connection Detection

A peer is considered connected if:

  • It has a non-zero latest_handshake timestamp
  • The handshake was within the last 180 seconds
connected = latest_hs > 0 and (now - latest_hs) < 180

Enrichment

Raw WireGuard data is enriched with friendly names and context:

Interface Friendly Name Purpose
strato-host Admin VPN admin
strato-vm VM Access VPN admin
openclaw-ai AI Tunnel ai

API Response

GET /api/vpn/status

{
  "error": null,
  "tunnels": {
    "strato-host": {
      "name": "Admin VPN",
      "description": "Laptop → Host admin access + DNS",
      "subnet": "10.0.0.0/24",
      "purpose": "admin",
      "listen_port": 51820,
      "status": "connected",
      "peer_count": 1,
      "peers": [
        {
          "endpoint": "91.7.98.176:54682",
          "allowed_ips": "10.0.0.2/32",
          "connected": true,
          "handshake_ago": 50,
          "transfer_rx": 1300976,
          "transfer_tx": 4061948
        }
      ]
    }
  }
}

Status Values

Status Meaning
connected At least one peer has a recent handshake
waiting No peers have connected recently

Error Handling

Error Cause
"wg command not found" wireguard-tools not installed in container
"..." (stderr) wg show command failed

The Dockerfile includes wireguard-tools specifically for this functionality.

Frontend Display

The VPN Tunnels tab shows cards for each tunnel:

  • Connected tunnels have a green left border
  • Waiting tunnels have an orange left border
  • Each card shows: name, interface, status badge, subnet, port, peer endpoint, handshake time, transfer stats
  • AI tunnels are tagged with a purple "AI TUNNEL" label
  • Admin tunnels are tagged with a blue "ADMIN" label

Dashboard Integration

The main Dashboard shows a VPN summary card:

VPN Tunnels: 2/3 connected

This is derived from status.vpn.connected_tunnels / status.vpn.total_tunnels.