Save 35% on the LionVPN annual planGet the Deal

LionVPN installation and usage — 0.1.3-rc.1

Localized explanation of the original signed Chinese README, not an independent test report. Device and architecture choices below are source declarations, not verified compatibility. Real-device installation, ABI/dependencies, VPN connection, DNS/routing and stability remain untested; complete source-to-binary binding is unestablished. This RC does not certify stable support.

Choose a package matching your device architecture and operating system. Before installation, check the download source, SHA256 and signature. Keep your existing configuration; disconnect the VPN and stop the service before upgrading or uninstalling.

Linux

Debian / Ubuntu: install the selected local .deb file with apt. Fedora / Rocky / AlmaLinux: install the selected local .rpm file with dnf. Generic archive: extract it, enter the package directory and run sudo sh scripts/install-linux.sh.

TUN, iproute2, nftables/iptables and CA certificates are required. After installation, review /etc/peervpn/peervpnd.json and configure it for your network, then start the service with sudo systemctl enable --now peervpnd. Packages do not enable the service automatically.

Use lionvpn doctor to check the environment, lionvpn login to sign in, lionvpn connect to connect, lionvpn status to view status and lionvpn disconnect to disconnect. See lionvpn -h for arguments. Add only trusted users to the peervpn group; this group can control VPN network settings.

OpenWrt

Firmware 24.10 uses IPK and 25.12 uses APK; the package architecture must match the device. The original document selects aarch64_cortex-a53 for Redmi AX6000 and x86_64 for x86 routers. Install through the corresponding firmware package manager, then configure the account and node on the LionVPN service page in LuCI.

OpenWrt uses UCI/procd to manage configuration and services. Keep the default gateway_dns_listen=127.0.0.1:1053; dnsmasq provides DNS for the LAN. Do not overwrite the generated OpenWrt configuration with a Linux JSON example.

Console gateway

Connect Xbox, PlayStation or Switch to the configured gateway network using ordinary Ethernet or Wi-Fi. See the original Chinese console-gateway.md below. Configure a dedicated LAN/VLAN/SSID and DHCP on the gateway beforehand. Changing only the console DNS does not route all traffic through the VPN. NAT type depends on the ISP, VPN server and upstream router.

Configuration and credentials

Accounts and sessions are created after users sign in; they are not supplied in the package. Do not share personal login files, passwords, tokens or device backups. Upgrades preserve the existing main configuration. Before deleting configuration, make your own backup and check for personal information.

Release candidate acceptance

The local RC uses a separate test signature; this does not establish production repository trust. The current APK outer package has no repository signature. Independently verify its source and checksums before deployment. Actual firmware, account connections, game matchmaking, voice and sleep/wake must be accepted on the target device.

Local candidate packages

Version: 0.1.3-rc.1. Linux amd64/arm64 packages are in packages/deb, packages/rpm and packages/tar; AX6000 and x86_64 packages for OpenWrt 24.10.2 and 25.12.0 are in the respective firmware directories.

This is a recompiled native-component release with the same application version. If that version is already installed, use the package manager’s reinstall function. Internal build paths were removed from native programs, and component hashes, public keys and signatures were updated. OpenSSL uses standard system directories; VPN business logic and other components remain unchanged.

Run sha256sum -c SHA256SUMS in the original release directory (on macOS: shasum -a 256 -c SHA256SUMS) to verify all files. SHA256SUMS.sig is the Base64 Ed25519 signature of that manifest; release-public-key.txt is this local candidate’s release public key. The packaged runtime-dependencies.pub is the component-manifest public key. They serve different purposes. This check does not establish production repository trust for APK or RPM.