███╗ ███╗ ██████╗ █████╗ ██╗ ██╗ ████╗ ████║██╔═══██╗██╔══██╗██║ ██║ ██╔████╔██║██║ ██║███████║██║ ██║ ██║╚██╔╝██║██║ ██║██╔══██║╚██╗ ██╔╝ ██║ ╚═╝ ██║╚██████╔╝██║ ██║ ╚████╔╝ ╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═╝ ╚═══╝
Multi-protocol Internet censorship circumvention stack
optimized for hostile network environments
Internet access is a human right. MoaV exists because censorship shouldn't.
When a government throttles or shuts down the internet, people lose access to their basic digital rights and cannot reach their families. MoaV turns a single server into a censorship-resistant gateway that runs 16+ circumvention protocols at once, so the moment one is blocked, traffic fails over to another.
Run it for yourself, share access with people you trust, or donate spare bandwidth to networks that reach millions living under shutdowns.
Single command setup. Docker Compose handles the rest. No manual configuration needed.
Create, revoke, and manage users independently. Each user gets unique credentials.
If one protocol is blocked, others can take over. Multiple layers of redundancy.
Works with popular clients on iOS, Android, macOS, Windows, and Linux.
All traffic looks like normal or garbled HTTPS, WebSocket, DNS, or IMAPS. Decoy website included.
Run your own, Audit the code, and Contribute to the code.
Your server can help millions. Donate bandwidth to Psiphon Conduit, Tor Snowflake, and Mahsa VPN.
Free for everyone, always. No subscriptions, no accounts, no paywalls. MIT licensed.
From zero to all protocols running in minutes
Demo coming soon
Demo coming soon
Web-based admin panel
Prometheus stats, user management, config bundles, MahsaNet donations
Demo coming soon
Real-time metrics
Per-user traffic, protocol breakdown, country distribution
Config bundles with QR codes
Zip, share, scan, connect
┌───────────────┐ ┌───────────────┐
┌───────────────┐ │ Psiphon Users │ │ Tor Users │
│ Clients │ │ (worldwide) │ │ (worldwide) │
│ (private) │ └───────┬───────┘ └───────┬───────┘
└───────┬───────┘ │ │
│ │ │
├─────────────────┐ │ │
│ │ Route through CDN │ │
│ ┌──────┴───────┐ │ │
│ │ Cloudflare / │ │ │
│ │AWS CloudFront│ │ │
│ └──────┬───────┘ │ │
│ │ │ │
┌──────────────╪─────────────────╪────────────────────────────────────╪──────────────────╪─────────┐
│ │ │ Restricted Internet │ │ │
└──────────────╪─────────────────╪────────────────────────────────────╪──────────────────╪─────────┘
│ │ │ │
╔══════════════╪═════════════════╪═══════════ MoaV Server ════════════╪══════════════════╪═════════╗
║ │ │ │ │ ║
║ ┌────────┼─────────────────┼───────┼──────┐ │ │ ║
║ │ │ │ │ │ │ │ │ ║
║ ▼ ▼ ▼ ▼ ▼ ▼ ▼ ▼ ║
║ ┌─────────┐┌─────────┐┌───────┐┌─────────┐┌────────┐ ┌───────────┐ ┌───────────┐ ║
║ │ Reality ││WireGuard││ Trust ││ DNS ││Telegram│ │ │ │ │ ║
║ │ 443/tcp ││51820/udp││Tunnel ││ 53/udp ││MTProxy │ │ Conduit │ │ Snowflake │ ║
║ │ Trojan ││AmneziaWG││4443/ │├─────────┤│993/tcp │ │ (donate │ │ (donate │ ║
║ │8443/tcp ││51821/udp││tcp+udp││ dnstt │└───┬────┘ │ bandwidth)│ │ bandwidth)│ ║
║ │Hysteria2││wstunnel ││ ││Slipstrm │ │ └─────┬─────┘ └─────┬─────┘ ║
║ │ 443/udp ││8080/tcp ││ │└────┬────┘ │ │ │ ║
║ │ CDN WS │└────┬────┘└───┬───┘ │ │ │ │ ║
║ │2082/tcp │ │ │ │ │ ┌────────────────┐ │ │ ║
║ ├─────────┤ │ │ │ │ │ Grafana :9444 │ │ │ ║
║ │ sing-box│ │ │ │ │ │ Prometheus │ │ │ ║
║ └────┬────┘ │ │ │ │ └────────────────┘ │ │ ║
║ │ │ │ │ │ │ │ ║
╚══════╪══════════╪═════════╪═════════╪═════════╪═════════════════════╪══════════════════╪═════════╝
│ │ │ │ │ │ │
▼ ▼ ▼ ▼ ▼ ▼ ▼
┌─────────────────────────────────────────────────────────────────────────────────────────────────┐
│ Open Internet │
└─────────────────────────────────────────────────────────────────────────────────────────────────┘
From zero to running in minutes. Use the one-liner setup.
Set up MoaV on my Linux server, moav.sh/llms.txt
curl -fsSL moav.sh/install.sh | bash
Installs requirements, clones MoaV, prompts for domain/email/password, and starts the interactive setup.
git clone https://github.com/MotherofallVPNs/moav.git cd moav ./moav.sh
moav # Interactive menu moav status # Service status & health moav doctor # Diagnose common issues moav help # All commands
After installation, use moav from anywhere. Run moav help for all commands.
Download user bundles from the admin dashboard at https://your-server:9443. Each bundle includes a readme.html with client setup instructions for every protocol.
Prefer an always-on local proxy with a dashboard, load-balancing, and automatic failover? Run the self-hosted MoaV Client.
Multiple protocols, one stack. If one is blocked, others take over.
443/tcp443/udp8443/tcp8445/tcp8388/tcp+udpCDN2096/tcpXray-core993/tcp51820/udp8080/tcp51821/udp4443/tcp+udp53/udpdns-router8444/tcpvia GooglePsiphon NetworkTor Networkconfig donationSee client apps to connect with these protocols.
Help keep the internet free and open
Deploy it on your server and help others connect. Every node strengthens the network.
Contribute on GitHub. Fix bugs, add features, improve docs. Every PR helps.
Try it with friends, report issues, share success stories. Real-world testing is invaluable.
MoaV is forever free and open source. If it helps you stay connected, please consider chipping in. Every bit keeps the network free and open.
MoaV (Mother of all VPNs) version 2.2.2 is a free, open-source, self-hosted censorship circumvention stack designed for countries with heavy internet censorship such as Iran, China, and Russia. It deploys 16+ anti-censorship protocols in a single Docker Compose command: Reality (VLESS) for TLS camouflage, XHTTP via Xray-core for multiplexed HTTP with Reality camouflage requiring no domain, Trojan for HTTPS mimicry, AnyTLS for defeating TLS-in-TLS fingerprinting, Hysteria2 for QUIC-based fast connections, Shadowsocks-2022 (AEAD-2022 ciphers with active-probing resistance, Outline-compatible), TrustTunnel for HTTP/2 and QUIC tunneling, AmneziaWG for DPI-resistant obfuscated WireGuard, CDN mode routing VLESS through Cloudflare or AWS CloudFront, standard WireGuard with optional WebSocket tunneling, four DNS tunnels — dnstt, Slipstream (QUIC-over-DNS), MasterDNS (ARQ + resolver load-balancing, native to MahsaNG v16), and XDNS (Xray-core FinalMask) — that all run simultaneously on port 53 via the dns-router (fanned out by subdomain) and work during heavy internet shutdowns, Telegram MTProxy with anti-DPI tuning (17 configurable settings), GooseRelay for SOCKS5 tunneled through a user-deployed Google Apps Script fronted as google.com (MahsaNG v16), Psiphon Conduit for bandwidth donation, Tor Snowflake for Tor network support, and MahsaNet config donation to Mahsa VPN (12M+ users worldwide).
Key features include: GeoIP country distribution showing where users connect from on Grafana dashboards (powered by DB-IP Lite, fully offline), web-based admin dashboard on port 9443 with Prometheus-backed aggregate stats across all protocols, Grafana monitoring on port 9444 with per-user traffic metrics and geographic distribution, MahsaNet/MahsaAlert integration to donate VPN configurations to Mahsa VPN (over 12 million users in Iran) using the 'moav donate' command, automatic protocol fallback when individual protocols are blocked, Docker security hardening with cap_drop ALL and read-only filesystems, multi-user credential management with downloadable config bundles and QR codes, moav doctor diagnostics with DNS zone file export, shell autocompletion for bash and zsh, domainless deployment mode for servers without a domain name, and a decoy website with anti-fingerprinting randomization.
Installation: curl -fsSL moav.sh/install | bash. Source code: github.com/MotherofallVPNs/moav. License: MIT. The project has an active open-source community contributing via GitHub issues and pull requests.
Support the project