VPN Monitoring¶
The Control Center monitors WireGuard VPN tunnels in real-time by parsing the output of wg show all dump.
How It Works¶
Data Source¶
The wg show all dump command outputs tab-separated data with two line types:
Interface line (5 fields):
Peer line (9 fields):
Connection Detection¶
A peer is considered connected if:
- It has a non-zero
latest_handshaketimestamp - The handshake was within the last 180 seconds
Enrichment¶
Raw WireGuard data is enriched with friendly names and context:
| Interface | Friendly Name | Purpose |
|---|---|---|
strato-host |
Admin VPN | admin |
strato-vm |
VM Access VPN | admin |
openclaw-ai |
AI Tunnel | ai |
API Response¶
GET /api/vpn/status¶
{
"error": null,
"tunnels": {
"strato-host": {
"name": "Admin VPN",
"description": "Laptop → Host admin access + DNS",
"subnet": "10.0.0.0/24",
"purpose": "admin",
"listen_port": 51820,
"status": "connected",
"peer_count": 1,
"peers": [
{
"endpoint": "91.7.98.176:54682",
"allowed_ips": "10.0.0.2/32",
"connected": true,
"handshake_ago": 50,
"transfer_rx": 1300976,
"transfer_tx": 4061948
}
]
}
}
}
Status Values¶
| Status | Meaning |
|---|---|
connected |
At least one peer has a recent handshake |
waiting |
No peers have connected recently |
Error Handling¶
| Error | Cause |
|---|---|
"wg command not found" |
wireguard-tools not installed in container |
"..." (stderr) |
wg show command failed |
The Dockerfile includes wireguard-tools specifically for this functionality.
Frontend Display¶
The VPN Tunnels tab shows cards for each tunnel:
- Connected tunnels have a green left border
- Waiting tunnels have an orange left border
- Each card shows: name, interface, status badge, subnet, port, peer endpoint, handshake time, transfer stats
- AI tunnels are tagged with a purple "AI TUNNEL" label
- Admin tunnels are tagged with a blue "ADMIN" label
Dashboard Integration¶
The main Dashboard shows a VPN summary card:
This is derived from status.vpn.connected_tunnels / status.vpn.total_tunnels.