📘 User Guide

Everything about AK VPN, step by step: how it works, how to set up each device, and how to use every feature.

1. Basics

💡

How AK VPN works

AK VPN is your own private network on the internet. Every device you add (phone, PC, MikroTik router) connects to the AK VPN server through an encrypted WireGuard tunnel. Once connected, your devices can reach each other as if they were in the same office, wherever they are.

  1. The server (194.61.31.50) is the meeting point. Your devices always connect out to it, so you need no static IP and it works on Jio/Airtel mobile data, broadband and any Wi-Fi.

  2. Every device gets a fixed VPN IP, for example 10.50.0.33. This address never changes (unless the admin changes it), so you can save it in your apps.

  3. Your own block: all your devices are in one private block (for example 10.50.0.32/27, up to 30 devices). Your devices can talk to each other. Other customers can never reach your devices: the server blocks it.

  4. Your internet stays as it is: only traffic for the VPN (10.50.0.0/16 and your site LANs) goes through AK VPN. YouTube, WhatsApp and normal browsing keep using your own internet, so nothing becomes slow.

  5. Port forwarding (optional): a public port on the server (for example 194.61.31.50:20001) can send traffic to one of your devices, so a service can be opened from the internet without the VPN app.

💡 Tip: The free official WireGuard app does all the work on your devices. AK VPN gives you the ready-made settings as a QR code, a .conf file or a MikroTik script.
↑ Back to top
🧰

What you need before you start

A short checklist. You can do everything from your phone.

  1. An AK VPN account with an active plan (see "Create your account" below).

  2. The WireGuard app on each phone or PC: use the Download app button on the home page, or the buttons on each device page in the panel.

  3. For a MikroTik router: RouterOS version 7 or newer (WireGuard is built in). Check in Winbox → System → Resources (version).

  4. For CCTV remote viewing: a MikroTik router (or another WireGuard device) at the camera site, connected to the same LAN as the DVR/NVR.

↑ Back to top

2. Your account

👤

Create your account and log in

Your account is where you add devices, download settings and manage port forwards.

  1. Open https://vpn.akdwk.in and tap Login. If you do not have an account, tap Create free account (if sign-up is open), or ask AK Computer to create one for you.

  2. To sign up: fill in Name, Email, Mobile number, Password (at least 10 characters with letters and numbers), tick the terms and tap Create account.

  3. Open the confirmation email and tap the link. Your account becomes active (or waits for approval by AK Computer, then you get an email).

  4. Log in with your email and password. You land on the Dashboard: your plan, online devices, active forwards and data used.

💡 Tip: Change language (English / ગુજરાતી) and light/dark theme with the buttons at the top, or in Profile.
↑ Back to top
🔐

Password, 2FA and account safety

Keep your account safe with a strong password. Optional two-factor login (2FA) adds a 6-digit code from your phone to every login.

  1. Open Profile (your name in the menu) → Manage 2FA.

  2. Install Google Authenticator, Microsoft Authenticator or Authy on your phone.

  3. Scan the QR code shown on the page with that app (or type the key shown below it).

  4. Type the 6-digit code from the app and tap Turn on 2FA. From now on, every login asks for the current code.

  5. To change your password: Profile → Change password. All other logged-in sessions are signed out.

  6. Forgot your password? On the login page tap Forgot password?, enter your email and use the link you receive (valid 1 hour).

⚠ Important: After 5 wrong passwords the account is locked for 15 minutes. Wait, then try again.
⚠ Important: 2FA is optional for customers and admins, and required for resellers. If you lose the phone with the codes, ask the admin to Reset 2FA.
↑ Back to top
📋

Plans, limits and renewal

Your plan decides how many devices and port forwards you can have, and until when.

  1. See your plan on the Dashboard or in Profile: name, valid until date, number of devices and port forwards.

  2. You get a reminder email 3 days before the plan ends.

  3. When the plan ends, your devices and port forwards stop working automatically. Nothing is deleted: names, IPs, settings and forwards are kept.

  4. After renewal by AK Computer or your reseller, everything starts working again by itself. You do not need to set up the devices again.

↑ Back to top

3. Set up your devices

➕

Add a device in the panel

Do this once for every phone, PC or router that should join your VPN. Each device gets its own settings and its own fixed VPN IP.

  1. Log in and open Devices → Add device.

  2. Device name: something you will recognise, for example "Akshay phone" or "Office PC".

  3. Device type: choose Android, iPhone, Windows, macOS, Linux or MikroTik v7.

  4. Site-to-site (MikroTik / router LAN): only for routers. Enter the LAN behind the router, for example 192.168.88.0/24 (see "Connect a branch office").

  5. Tap Create device. The device page opens with the QR code, Download .conf and, for MikroTik, the script.

⚠ Important: The private key is shown only once on that first page. The QR and the file can be downloaded again later from the device page (unless the admin turned this off).
💡 Tip: Your plan limits how many devices you can add. The page shows "Devices used: x of y".
↑ Back to top
🤖

Android phone or tablet

Takes about one minute.

  1. On the phone, install WireGuard from the Play Store (home page → Download app, or Android (Play Store) on the device page). No Play Store? Use Android APK.

  2. In the panel, open the device and keep the QR code on the screen. Open the panel on a PC, or on a second phone, to scan it.

  3. Open WireGuard → tap the blue + → Scan from QR code → allow the camera → scan.

  4. Give the tunnel a name (for example akvpn) and tap Create tunnel.

  5. Switch the tunnel on and tap OK when Android asks to allow a VPN connection. A key icon appears in the status bar.

  6. Check: in the panel the device shows Online within a minute.

💡 Tip: Only one phone? Tap Download .conf on the phone, then in WireGuard: + → Import from file or archive → choose the downloaded file.
💡 Tip: For "always on": Android Settings → Network → VPN → WireGuard ⚙ → Always-on VPN.
↑ Back to top
📱

iPhone or iPad

Takes about one minute.

  1. Install WireGuard from the App Store (home page → Download app, or iPhone (App Store) on the device page).

  2. Show the device's QR code on another screen (PC or second phone).

  3. Open WireGuard → Add a tunnel (or +) → Create from QR code → allow the camera → scan.

  4. Type a name (for example akvpn) → Save, then tap Allow and confirm with Face ID / passcode to add the VPN configuration.

  5. Switch the tunnel on. "VPN" appears at the top of the screen.

  6. Check: the device shows Online in the panel.

💡 Tip: Only one iPhone? Tap Download .conf, then open the file from the Files app and choose WireGuard.
↑ Back to top
🪟

Windows 10 / 11 PC

Use this for office PCs, laptops and servers.

  1. Download the installer: home page → Download app → Download for Windows (.exe), or the Windows (.exe) button on the device page. Run it and allow the installation.

  2. In the panel, open the device and tap Download .conf. A file like akvpn-Office PC.conf is saved.

  3. Open WireGuard → Import tunnel(s) from file → choose the downloaded .conf file.

  4. Tap Activate. Status turns Active and the device shows Online in the panel.

  5. An activated tunnel starts again by itself after Windows restarts. You can close the WireGuard window; the tunnel keeps running.

⚠ Important: If other devices must reach this PC (Remote Desktop, file share, port forward), Windows Firewall must allow it. See "Reach your other devices" and "Port forwarding".
↑ Back to top
💻

macOS (MacBook, iMac)

Same as Windows, using the Mac App Store app.

  1. Install WireGuard from the Mac App Store (macOS (App Store) button).

  2. In the panel tap Download .conf.

  3. Open WireGuard → Import Tunnel(s) from File → choose the file → Allow the VPN configuration.

  4. Tap Activate. The device shows Online in the panel.

↑ Back to top
🐧

Linux PC or server

For Ubuntu / Debian. Other distributions: see wireguard.com/install.

  1. Install WireGuard:

    sudo apt install wireguard-tools
  2. In the panel tap Download .conf and copy the file to the machine.

  3. Install the config and start the tunnel:

    sudo cp akvpn-*.conf /etc/wireguard/akvpn.conf
    sudo chmod 600 /etc/wireguard/akvpn.conf
    sudo wg-quick up akvpn
  4. Start it automatically at boot:

    sudo systemctl enable wg-quick@akvpn
  5. Check the connection:

    sudo wg show
    ping 10.50.0.1
↑ Back to top
📡

MikroTik router (RouterOS v7)

Joins the router, and optionally the whole LAN behind it, to your VPN. No app needed: WireGuard is built into RouterOS v7.

  1. In the panel: Devices → Add device → Device type MikroTik v7. If the LAN behind the router should be reachable, open Site-to-site and enter the LAN, for example 192.168.88.0/24. Tap Create device.

  2. On the device page tap Copy script (or Download .rsc).

  3. Open Winbox and connect to the router → New Terminal.

  4. Paste the whole script and press Enter. It creates the interface akvpn, the AK VPN peer, the VPN address, the routes and the needed firewall rules. Re-running it later replaces the old AK VPN settings safely.

  5. Check it in the same terminal:

    /interface wireguard peers print
    /ping 10.50.0.1
  6. The device shows Online in the panel.

⚠ Important: Each LAN range must be unique. If 192.168.88.0/24 is already used by another AK VPN router, the panel refuses it: change the router's LAN (for example to 192.168.50.0/24) first.
⚠ Important: The MikroTik script never changes the router's own internet (no default route). Internet users at the site are not affected.
↑ Back to top
✅

Check that a device is connected

Two quick checks after any setup.

  1. In the panel open Devices. Online (green) means the device talked to the server in the last 3 minutes. The page refreshes by itself every 15 seconds.

  2. The device page also shows the last handshake, the data used (↓ / ↑) and the device's public address.

  3. On the device, test the tunnel by pinging the server's VPN address 10.50.0.1 (Windows: ping 10.50.0.1 in Command Prompt; MikroTik: /ping 10.50.0.1; phone: any "Ping" app).

↑ Back to top

4. Use it

🔗

Reach your other devices (Remote Desktop, file share, web)

All your devices can reach each other by their VPN IP (shown on each device page). Different customers can never reach each other.

  1. Find the VPN IP of the target device: Devices → open it → VPN IP (for example 10.50.0.34).

  2. Make sure both devices are Online.

  3. Remote Desktop: on the target Windows PC enable it (Settings → System → Remote Desktop → On). On your laptop or phone open Remote Desktop and connect to 10.50.0.34.

  4. File sharing: in Windows Explorer type \\10.50.0.34 in the address bar.

  5. Web page / DVR / router: open http://10.50.0.34 (or the device's port) in the browser.

  6. Windows blocks these by default on the VPN. On the target PC open PowerShell as Administrator and allow your VPN network (example for Remote Desktop, file share and ping):

    New-NetFirewallRule -DisplayName "AK VPN RDP+SMB" -Direction Inbound -Action Allow -Protocol TCP -LocalPort 3389,445 -RemoteAddress 10.50.0.0/16 -Profile Any
    New-NetFirewallRule -DisplayName "AK VPN ping" -Direction Inbound -Action Allow -Protocol ICMPv4 -RemoteAddress 10.50.0.0/16 -Profile Any
💡 Tip: Windows treats the WireGuard connection as a "Public" network, which is why the rule uses -Profile Any.
↑ Back to top
📹

Watch CCTV (DVR / NVR) from your phone

Works with Hikvision, CP Plus, Dahua and other DVR/NVRs. The DVR needs nothing extra; a MikroTik router at the site does the VPN part.

  1. At the camera site: the DVR/NVR and the MikroTik router are on the same LAN (for example DVR 192.168.88.20, router 192.168.88.1). The DVR's gateway must be the MikroTik.

  2. In the panel add the MikroTik as a device with Site-to-site LAN 192.168.88.0/24 and run its script (see "MikroTik router").

  3. Add your phone as a device after the MikroTik, or re-download / re-scan the phone's config after adding the MikroTik. The phone's config must include the site LAN.

  4. Turn the VPN on on your phone.

  5. In the CCTV app (Hik-Connect / iVMS-4500, gCMOB, DMSS…) add the device by IP / domain: address 192.168.88.20, port as on the DVR (often 8000 Hikvision, 37777 Dahua), with the DVR username and password.

  6. Live view and playback now work over the encrypted VPN, without a static IP or the maker's cloud.

💡 Tip: Want to open the DVR without the VPN app (for example for a client)? Use a port forward to the MikroTik plus a dst-nat rule on the router. See "Port forward to a device behind a MikroTik".
↑ Back to top
🏢

Connect a branch office (site-to-site)

Make a whole office LAN reachable from your phones, laptops and other offices.

  1. Give each office a different LAN range, for example office A 192.168.88.0/24, office B 192.168.50.0/24.

  2. For each office router: Add device → type MikroTik v7 → Site-to-site → enter that office's LAN → Create device → run the script on that router.

  3. Re-download or re-scan the configs of your phones/PCs (and re-run the scripts of other routers) so they learn the new LAN routes.

  4. From any of your devices you can now open computers in that office by their normal LAN IP, for example 192.168.88.10.

⚠ Important: Two sites with the same LAN (both 192.168.1.0/24) cannot both be published. Change one of them first.
↑ Back to top

5. Port forwarding

🌐

Open a service to the internet (port forward)

A port forward sends 194.61.31.50:<public port> to <device VPN IP>:<internal port>. People can then open that service from anywhere without the VPN app.

  1. Open Port forwards → Add forward.

  2. Label: what it is, for example "PC remote desktop" or "CCTV web".

  3. Public port: choose Pick a free port for me (easiest), or I want a specific port and type one between 20000 and 29999. The page checks it immediately.

  4. Device: the device that runs the service (must be Online).

  5. Internal port on the device: the service's port on that device, for example 3389 Remote Desktop, 80 web, 8000 Hikvision.

  6. Protocol: TCP (most services), UDP, or TCP + UDP.

  7. Tap Create forward. The list shows the public address, for example 194.61.31.50:20001.

  8. Allow the port on the device's own firewall (Windows: the command shown on the device page). Then the status turns Green.

💡 Tip: A device can have many forwards: one per service.
💡 Tip: Every config has keep-alive built in, so forwards also work for devices on Jio/Airtel mobile data.
↑ Back to top
🚦

Port status and messages explained

What the colours and messages in Port forwards mean.

  1. Green: the server could open the port through the tunnel; it works from outside. It is checked automatically (at most once a minute when you open the page); tap ⟳ to check now.

  2. Red: the port did not answer. The device is offline, the service is not running, or the device's firewall blocks it.

  3. n/a: UDP-only forwards cannot be tested with a connection test. Test them with the real app.

  4. Used by server: you asked for a port the server itself uses or reserves. Pick another one; the next free port is suggested.

  5. Already taken: another forward already uses that public port. Use the suggested free port.

  6. Suspended: the plan ended or the device is disabled. It comes back automatically after renewal or enabling.

  7. To remove a forward tap ✕. The port is freed immediately.

↑ Back to top
🔁

Port forward to a device behind a MikroTik (DVR, printer…)

For devices that cannot run WireGuard themselves, like a DVR. Example: DVR web on 192.168.88.20:80 behind a MikroTik with VPN IP 10.50.0.40.

  1. Create a port forward to the MikroTik device, internal port 80, protocol TCP. Note the public port, for example 20005.

  2. On the MikroTik (Winbox → New Terminal), send that port on to the DVR:

    /ip firewall nat add chain=dstnat in-interface=akvpn protocol=tcp dst-port=80 action=dst-nat to-addresses=192.168.88.20 to-ports=80 comment="akvpn DVR"
  3. Open http://194.61.31.50:20005 from anywhere. The DVR page opens and the forward shows Green.

↑ Back to top

6. Manage & troubleshoot

🛠

Manage devices (rename, disable, delete, new config)

Everything is on the device page: Devices → tap the device.

  1. Rename / change settings: edit the fields in Settings → Save.

  2. Disable: the device is disconnected at once but kept (name, IP, forwards). Enable brings it back with the same settings.

  3. Delete: removes the device and all its port forwards for good. Delete the tunnel in the WireGuard app too.

  4. Lost phone? Disable or delete its device immediately: the lost phone can no longer connect.

  5. "New config" badge: the admin changed this device's VPN IP. The old config no longer connects. In the WireGuard app delete the old tunnel, then scan the new QR or import the new file from the device page.

↑ Back to top
📊

Data usage and uptime reports

See how much data each device used per day and per month, and when it was online or offline.

  1. Open Usage in the menu: a chart of all your devices together for the last 30 days (or 90 days), the data of this month per device, and the monthly totals.

  2. Each device page shows its own Data usage chart (download in blue, upload in orange) and the Uptime strip: one block per day, green = online 99% or more, yellow = 90-99%, red = below 90%.

  3. Move the finger or mouse over a bar or block to see the exact numbers for that day. Show as table lists every day as text.

  4. Tap Full report on the device page for the monthly table, the online / offline history (when it went offline, when it came back, how long) and Download CSV (opens in Excel).

  5. The Dashboard tile Data this month shows the total of all your devices.

💡 Tip: Recording starts automatically and is updated every minute. Data is kept for about 13 months, online/offline history for 6 months.
💡 Tip: A device that keeps going offline at the same time every day usually has a power cut or a router restart at that time.
↑ Back to top
🩺

Troubleshooting

Most problems are solved by one of these checks.

  1. Device stays Offline: is the tunnel switched on in the app? Does the device have internet? Is the plan active (Dashboard)? Is the device Enabled? Then switch the tunnel off and on.

  2. Online, but cannot open another device: is the target Online too? Is its firewall allowing it (see "Reach your other devices")? Did you use the VPN IP (10.50.x.x) or the site LAN IP?

  3. Cannot reach a site LAN (CCTV, office): re-scan / re-download your phone's config after the MikroTik was added, check the MikroTik with /ping 10.50.0.1, and check that the DVR's gateway is the MikroTik.

  4. Port forward is Red: device Online? Service running? Port allowed in the device firewall? Correct internal port and protocol?

  5. "New config" or the tunnel suddenly stopped after an IP change: delete the old tunnel and import the new QR/file.

  6. Login problems: wait 15 minutes after a lockout; use Forgot password?; lost 2FA phone → ask the admin to reset 2FA.

💡 Tip: Still stuck? Send AK Computer a screenshot of the device page and of the WireGuard app.
↑ Back to top

7. Resellers & admin

🤝

For resellers: manage your customers

Resellers create and manage their own customers. Customers of other resellers are never visible.

  1. Open Users → Add user: name, email, phone, password, language and a Plan. Tap Save.

  2. Open a customer to renew: in Plan choose the plan (and optional days) → Assign / renew. Renewing the same plan before it ends adds the days to the current end date.

  3. Add devices for a customer: Devices → Add device → choose the Owner.

  4. Add port forwards for a customer's device: Port forwards → Add forward → choose their device.

  5. Disable a customer: open them → Status Disabled → Save. All their devices stop at once; data is kept.

⚠ Important: Reseller accounts must use 2FA.
↑ Back to top
🛡

For the admin: admin device (access to all customer networks)

An admin device is your own support phone or laptop that can open every customer device and every site LAN (CCTV, office networks, MikroTik routers). Access is one-way: customers cannot open the admin device, and customers stay isolated from each other.

  1. Add the device under your own admin account: Devices → Add device → Owner = you. Set it up like any other device.

  2. Open the device page → Admin device → Make admin device → confirm. Only devices of admin accounts can get this.

  3. Download the config again (or re-scan the QR). The new config routes all customers' site LANs into the tunnel.

  4. Open Network in the menu to see every customer's block, device names, VPN IPs, site LANs and port forwards. Use the search box to find a customer, device, IP or LAN.

  5. Connect to any address from the list, for example Remote Desktop to 10.50.0.34, a DVR at 192.168.88.20 or Winbox to a customer's MikroTik VPN IP.

  6. To stop it: device page → Turn off admin device.

⚠ Important: After customers add new sites, download the admin device config again so it gets the new LAN routes.
⚠ Important: If your own home/office LAN uses the same range as a customer LAN (for example both 192.168.1.0/24), that customer LAN cannot be reached while you are on that local network.
⚠ Important: First time only: update the agent on the server with sudo bash /www/wwwroot/vpn.akdwk.in/scripts/update-agent.sh.
💡 Tip: To open a customer's MikroTik itself (Winbox), the customer's router script must be re-run once after the admin device is created; it then allows your admin block.
↑ Back to top
⚙

For the admin: settings, updates and backups

Only the Super Admin sees these menus.

  1. Plans: Plans → Add plan: price, device limit, forward limit, validity days.

  2. Self-registration: Settings → Customer self-registration: turn on sign-up, choose if accounts need approval, and set an optional trial plan and trial days. Waiting customers show on the Dashboard; approve them by setting Status to Active (approve).

  3. Front page contact: Settings → phone, WhatsApp, email and address for the public pages.

  4. Change a device IP: device page → Fixed VPN IP → Change IP. The device is disconnected, its owner is emailed and must import the new config.

  5. Reserved ports: Settings → Reserved ports: ports that are never given to customers.

  6. Updates: Updates → Check for update → Update now. A backup is made first; a failed update is rolled back automatically. Old backups can be restored from the same page.

  7. Sync server from database: Dashboard or Settings. Re-applies every device and forward on the server; safe to press at any time.

  8. Audit log: every login, change and server action, with time, user and IP.

↑ Back to top

Still need help?

AK Computer, Dwarka can set up your devices, MikroTik router and CCTV for you.

Login ☰ Contents