Preflight
Flirexa checks the remote operating system, SSH authentication, required ports, package availability, existing firewall state, and whether a supported protocol can be installed safely.
Multi-location operations
Add a compatible server by providing temporary SSH access, let Flirexa install and verify the agent, then manage customers, traffic, health, and configuration delivery without maintaining a different toolchain for every location.
Adding a location
The remote node is intentionally smaller than the control server. It runs the VPN endpoint and Flirexa agent while the main installation owns customers, plans, payments, and policy.
Flirexa checks the remote operating system, SSH authentication, required ports, package availability, existing firewall state, and whether a supported protocol can be installed safely.
The panel installs the minimal managed components, generates the agent API key, creates its system service, enables the selected VPN endpoint, and records the node in the control database.
Health, API authentication, interface state, forwarding, and required networking are checked before the location is treated as ready for customers.
Central operations
The panel decides where a customer belongs and renders the correct configuration from authoritative server and device data. Operators can see the same customer from the global list, the server view, the portal account, and support workflows.
Production discipline
Flirexa can place configured resolver addresses into generated WireGuard and AmneziaWG profiles. If you operate Unbound or filtered DNS, deploy and monitor that resolver separately on every node that advertises it.
The bootstrap configures the required forwarding and NAT path for the supported node profile. Existing custom UFW, iptables, nftables, provider firewall, or Docker rules still need an operator review.
A server migration succeeds only when the replacement is compatible with the protocol and key material expected by existing configurations. Export sensitive keys only for an authorized migration and keep them out of tickets and public repositories.
Measure CPU, bandwidth, packet loss, route quality, provider limits, and actual concurrent use. The licence limit is not a performance guarantee for the VPS underneath it.
Plan boundary
| Plan | Server model | Typical use |
|---|---|---|
| FREE | Installation host only, one local WireGuard and one local AmneziaWG endpoint | Evaluation, personal use, or a small single-host service |
| Starter | Installation host, with the additional paid protocol set | One location that needs Hysteria2, TUIC, or VLESS-Reality |
| Business | Up to 10 managed servers | A commercial service offering several countries or capacity pools |
| Enterprise | Unlimited managed servers | Large networks, MSPs, ISPs, full white-label, and scoped operator teams |
Questions
Use a fresh supported server and let the current Add Server flow perform its preflight and managed bootstrap. Installing a parallel VPN stack or conflicting firewall policy first creates more work, not a cleaner node.
Yes. Server DNS can be edited, and Business per-device DNS modes can point to resolver addresses you operate. Enterprise adds custom profiles and enforced policy scopes.
No. Operational counters and connection state are different from traffic-content logging. If you add a DNS resolver with query logging or external network monitoring, its privacy behavior is your responsibility.
Yes. Update the endpoint in the panel. Official applications receive it on the next configuration refresh; manually downloaded profiles must be downloaded again.