First hour after VPN install
First hour after a vpn install with AmneziaVPN: open the app, deploy or import, prove a tunnel, then keep one update door.
By Mist Latch editorial team Current release, published August 21, 2026
The install only pays off when one tunnel works. Use the checklist below on the same machine that just received AmneziaVPN. Longer OS paths live under guides.
Eight first-hour steps
- Launch AmneziaVPN Open AmneziaVPN from the Start menu, Applications, or desktop launcher so the main client window appears.
- Choose deploy or import Enter a server IP with SSH credentials to deploy vpn containers, or import an existing supported configuration.
- Pick a protocol Choose WireGuard, AmneziaWG, OpenVPN, or another supported protocol for this first proof.
- Prove one site through the tunnel Load a known site through the new tunnel before you add split-tunnel rules or extra devices.
- Note the update door Write whether this machine used the Windows x64 exe, winget, macOS pkg, Linux .run, or an Android APK.
- Optional split tunneling later Only after the proof works, add site or app split-tunnel rules if you need them.
- Keep server notes nearby Record the VPS hostname, SSH user, and protocol on the machine ticket.
- Skip Softonic updaters Return to GitHub Releases or winget for updates. Refuse third-party vpn updaters from search ads.
What success looks like
Success is a site that loads through the tunnel with the protocol you expected. Success is not three download folders full of renamed setups. If the first tunnel fails, re-check SSH credentials and that the VPS accepts Docker installs before you download another mirror.
SmartScreen or Gatekeeper prompts are common on first launch. Prefer the Releases URL or winget command you typed yourself. First run detail: first run. Safety: is it safe.
Windows notes
Prefer AmneziaVPN_*_windows_x64.exe from a Windows-bearing tag. winget id AmneziaVPN.AmneziaVPN is an alternate channel. Windows guide: install on Windows.
macOS notes
Open the matching pkg from Releases and finish Gatekeeper prompts. macOS guide: install on macOS.
Linux notes
chmod +x the .run, then execute it. Linux guide: install on Linux.
After the proof tunnel
Open more devices only after the proof works. Switch habits from commercial apps with switch from commercial vpn apps. Compare options on vs commercial vpn apps.
Document the update door on the machine ticket. Shared desks lose hours when nobody remembers whether winget or the Windows exe owns the next bump.
Mistakes in the first hour
Downloading a second Softonic copy to fix a blocked first run. Expecting a managed commercial fleet without deploying a server. Uploading credentials into chat “just to compare”. Skipping the proof tunnel and jumping into split-tunnel rules.
Fix each mistake the same way: one honest door, one proven tunnel, one documented path. Self-host: self-host server.
Related doors
Home: home. Releases: releases. Download safe: download safe. Machine chooser: for this computer. Update and uninstall: update uninstall.
Repeat the proof after reimages
Lab images drift. After every reimage, prove one short tunnel again before you call the desk ready. That habit catches missing winget sources, vanished installers, and Softonic shortcuts that reappear from old bookmark exports.
Write the AmneziaVPN update door on the ticket beside the OS version. Windows exe, winget, macOS pkg, Linux .run, and Android APK are different doors. Mixing them without notes creates duplicate installs and confused uninstalls.
Server notes belong on the ticket
Write the VPS hostname, SSH user, and protocol beside the installer door. Shared desks lose hours when the client is present but nobody remembers which host still runs the containers. Prefer one documented server per machine unless you intentionally operate a lab fleet.
If SSH credentials were pasted into chat during setup, rotate them after the proof tunnel works. Treat the first hour as both a client checklist and a light operations handoff.
Keep the job name clear
This first hour is for self-hosted vpn work on a server you control. It is not a commercial seat checklist. Keep sources on Releases, keep AmneziaVPN updated from the same door you used on day one.
Mist Latch publishes the install guide. Upstream AmneziaVPN remains at amnezia.org and GitHub. When Releases change which OS assets appear, re-check the live tag before you image a lab.