Repository navigation
VPN Configuration
NetWatch requires a full-tunnel WireGuard configuration for its backend services. The managed tunnel is their required Internet route; a Windows host VPN is optional and does not replace it.
- Select Generic WireGuard or VPNBook during setup.
- Choose the provider
.conffile. - Wait for NetWatch to validate the profile, start the managed runtime, and check routing, DNS, the kill switch, and Internet egress.
NetWatch rejects provider command hooks and profiles that do not supply a full IPv4 tunnel and an IPv4 DNS resolver. Imported profiles are rewritten into NetWatch's managed format.
Generic WireGuard and VPNBook use the same secure routing path. The VPNBook expiry date is an estimate for renewal planning, not a security verdict.
- Open Settings and select Replace configuration.
- Import the new provider file.
- Restart NetWatch when prompted.
- Run Test connection after the runtime returns to Ready.
The replacement is applied during restart; it is not a live tunnel swap.
If you start, stop, or switch a Windows host VPN, restart NetWatch so Docker and WSL networking can settle against the new host route.
Run the bundled network check from PowerShell:
wsl -d Ubuntu -- sh -lc 'cd ~/.local/share/netwatch/runtime && python3 docker/verify-networking.py'Replace Ubuntu with the distribution selected for NetWatch. The output identifies routing, DNS, firewall, or egress failures without displaying the private key.
The maintained security guarantees and limitations are in the network threat model.
NetWatch Wiki
Setup
- Getting Started
- Windows Installation
- Android Companion Setup
- Pairing and Remote Access
- VPN Configuration
- Prowlarr and FlareSolverr
Using NetWatch
Help
Development