All Activity
This stream auto-updates
- Past hour
-
-
-
-
-
-
-
-
-
-
- Today
-
Thank you. However, I think it is not possible to upgrade to OpenVPN 2.4 on DSM6 which can only stick to OpenVPN 2.3. Also I'm not able to install Wireguard client as tailscape package is not compatible with my Synology model DS413 because of CPU restriction. So it seems I don't have any solution anymore to connect my DS413
-
Hello! Please upgrade to OpenVPN 2.4 or higher version, or switch to WireGuard alternatively. The OpenVPN version you're running doesn't support AES-GCM (or CHACHA20) on the Data Channel. Due to remarkable demand for DCO (Data Channel Offload kernel module to speed up OpenVPN throughput and make it more scalable through multiple threads) AirVPN servers, ever since migration to DCO was completed, do not support AES-CBC because its activation, even as a fallback cipher only, would cause global OpenVPN daemon Data Channel Offload de-activation. Kind regards
-
I use DSM 6.2.4 which is the latest avail for my hardware. Also I get some more logs trying to connect from command line : Sat Sep 5 11:00:03 2026 OpenVPN 2.3.17 powerpc-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Mar 2 2021 Sat Sep 5 11:00:03 2026 library versions: OpenSSL 1.0.2u-fips 20 Dec 2019, LZO 2.09 Sat Sep 5 11:00:03 2026 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts Sat Sep 5 11:00:03 2026 PLUGIN_INIT: POST /lib/openvpn/openvpn-down-root.so '[/lib/openvpn/openvpn-down-root.so] [/usr/syno/etc.defaults/synovpnclient/scripts/ip-down]' intercepted=PLUGIN_UP|PLUGIN_DOWN Sat Sep 5 11:00:03 2026 WARNING: file 'client_key_o1788116283.key' is group or others accessible Sat Sep 5 11:00:03 2026 WARNING: file 'ta_o1788116283.key' is group or others accessible Sat Sep 5 11:00:03 2026 Control Channel Authentication: using 'ta_o1788116283.key' as a OpenVPN static key file Sat Sep 5 11:00:03 2026 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication Sat Sep 5 11:00:03 2026 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication Sat Sep 5 11:00:03 2026 Socket Buffers: R=[112640->112640] S=[112640->112640] Sat Sep 5 11:00:03 2026 UDPv4 link local: [undef] Sat Sep 5 11:00:03 2026 UDPv4 link remote: [AF_INET]37.46.199.83:443 Sat Sep 5 11:00:03 2026 TLS: Initial packet from [AF_INET]37.46.199.83:443, sid=e7d2db9f d9647ba7 Sat Sep 5 11:00:03 2026 VERIFY OK: depth=1, C=IT, ST=IT, L=Perugia, O=airvpn.org, CN=airvpn.org CA, emailAddress=info@airvpn.org Sat Sep 5 11:00:03 2026 Validating certificate key usage Sat Sep 5 11:00:03 2026 ++ Certificate has key usage 00a0, expects 00a0 Sat Sep 5 11:00:03 2026 VERIFY KU OK Sat Sep 5 11:00:03 2026 Validating certificate extended key usage Sat Sep 5 11:00:03 2026 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication Sat Sep 5 11:00:03 2026 VERIFY EKU OK Sat Sep 5 11:00:03 2026 VERIFY OK: depth=0, C=IT, ST=IT, L=Perugia, O=airvpn.org, CN=Fuyue, emailAddress=info@airvpn.org Sat Sep 5 11:00:06 2026 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1558', remote='link-mtu 1550' Sat Sep 5 11:00:06 2026 WARNING: 'cipher' is used inconsistently, local='cipher AES-256-CBC', remote='cipher AES-256-GCM' Sat Sep 5 11:00:06 2026 WARNING: 'auth' is used inconsistently, local='auth SHA1', remote='auth [null-digest]' Sat Sep 5 11:00:06 2026 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Sat Sep 5 11:00:06 2026 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Sat Sep 5 11:00:06 2026 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Sat Sep 5 11:00:06 2026 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Sat Sep 5 11:00:06 2026 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 4096 bit RSA Sat Sep 5 11:00:06 2026 [Fuyue] Peer Connection Initiated with [AF_INET]37.46.199.83:443 Sat Sep 5 11:00:08 2026 SENT CONTROL [Fuyue]: 'PUSH_REQUEST' (status=1) Sat Sep 5 11:00:08 2026 SYNO_ERR_AUTH Sat Sep 5 11:00:08 2026 AUTH: Received control message: AUTH_FAILED,Data channel cipher negotiation failed (no shared cipher) Sat Sep 5 11:00:08 2026 SIGTERM received, sending exit notification to peer Sat Sep 5 11:00:13 2026 SENT CONTROL [Fuyue]: 'PUSH_REQUEST' (status=1) Sat Sep 5 11:00:13 2026 PLUGIN_CLOSE: /lib/openvpn/openvpn-down-root.so Sat Sep 5 11:00:13 2026 SIGTERM[soft,exit-with-notification] received, process exiting Seems to be a pb with cipher but don't know where exactly
-
knighthawk reacted to a post in a topic:
Extremely low torrent speeds sinds last week despite correct port forwarding and WireGuard ...
-
knighthawk reacted to a post in a topic:
Extremely low torrent speeds sinds last week despite correct port forwarding and WireGuard ...
-
-
251 TB Uploaded / Share Ratio: 25.42 for me! What's yours?
- Yesterday
-
Time to establish a connection has been significantly sped up as well. Still working fine, but noticed I have to reconnect manually over night.
-
How To Set Up pfSense 2.3 for AirVPN
cl0Z1n10 replied to pfSense_fan's topic in General & Suggestions
in case someone can help... i have configured pfsense 2.4.3 using this guide. had to make some changes a couple of years ago. i have now had to "Enable Negotiable Cryptographic Parameters" in order for the openvpn client to connect. qbittorrent is no longer able to connect to peers - any ideas? win10ltsc - tried disabling defender firewall, but it didn't help -
-
-
ANSWERED trying to get air vpn to startup with linux machine
reader45 replied to reader45's topic in Troubleshooting and Problems
Well as i am using a systemd system it is either create a service so the application starts on boot or add the eddie ui to startup applications. I added eddie ui to startup as its easier and quicker when i was fiddling last night, Either will do the job, I also had to increase the delay on starting the apps that need the vpn to give Air time to connect and settle. The reason I asked what i was missing, Airvpn on windows does it for you if you select start at boot and the vpn i have been using but am dumping also did it for you on linux if you selected start at boot in gui config. I didnt want to go crashing in adding things if it wasn't necessary. -
I do still have this error from time to time, after multiple connects so that I have to quit and restart Eddie. After a clean restart of Eddie, it works for most of the time until I do a lot of additional connects. I am on macOS 26.5.2 Is there any indication on why and when this error could occur?
-
ANSWERED Gluetun + qbittorrent + port forwarding not working
traerin replied to traerin's topic in Troubleshooting and Problems
THANK YOU ITS WORKING -
Hello JesusxSaves, This thread began on 21 August with the announcement of the release of Eddie 2.26.2 Desktop Edition. On 2 September, I realised I’d overlooked this announcement regarding the release of the ‘stable’ version; I tested it again without success, and posted a comment to say that my issue with launching eddie-ui was still unresolved. Three hours later, you posted a comment beneath mine criticising the Eddie/AirVPN developers, writing that you’re capable of doing better than them at writing an entire graphical VPN client program using LLMs, and adding that you easily create games on Android using vibe coding. Perhaps I’m mistaken, but I get the slight impression that you’ve taken advantage of my post—in which I expressed my frustration at being stuck on version 2.25.1 of eddie-ui—to vent your own frustration. Even if the fact that you posted your message three hours after mine is a coincidence, I do not wish to be associated with what you wrote, and to remove any ambiguity: I am completely opposed to what you are claiming. I find that the way you phrase your criticisms in this post is rather inelegant, and disrespectful towards the eddie/AirVPN developers. It is possible that forum readers who are curious and keenly interested in all things relating to the vibe coding scene might be unduly influenced by the way you phrase your comments, and that this could lead to a certain amount of harmful pressure being placed on the eddie/AirVPN developers. That is why I would like to add my own perspective below: Low-level vs Graphical User Interface: The server and client software developed by the eddie/AirVPN team falls under the SECURITY category (not the Android gaming category). This requires a sound low-level understanding of operating systems, expertise in constantly evolving network protocols, security monitoring, and the ability to respond swiftly should any vulnerabilities be discovered. For security software developers, focusing on the low-level aspects is always a PRIORITY over the higher-level graphical user interface. The graphical user interface of the free software eddie-ui is becoming outdated, but it is not fundamentally incompatible with operating systems (for the time being). It is important to note that, despite all its minor flaws, eddie-ui remains a remarkable piece of software. Unlike the ‘flashy’ software from major VPN companies, the graphical user interface of the open-source eddie-ui is designed first and foremost with the aim of providing maximum freedom for the end user: it offers a vast range of configuration and customisation options, even in its mobile versions. All these graphical user interface controls, which allow for very fine-grained configuration of the underlying VPN client software (OpenVPN + WireGuard), must certainly have required a great deal of development time. I think that this freedom of choice for the end user is a hallmark of the eddie/AirVPN team’s ethical commitment. This is the spirit of free software as taught by Richard Stallman and the Free Software Foundation. Money: Companies with plenty of money tend to completely rewrite their software and graphical user interfaces in Rust, which automatically eliminates certain programming errors that can occur in C++. But AirVPN is a small organisation that has no intention of becoming a start-up funded by private equity. Vibe coding: LLMs are powerful tools for computer programming. But they must be used wisely and with great caution. Starting to have an LLM agent do all the work from A to Z by giving it interface objectives amounts to taking the very high risk of no longer manually checking the underlying code (see the French case of Benjamin Code), and of introducing security vulnerabilities. Just a few days ago, on 30 August 2026, reputable figures such as the Debian developers decided to authorise the use of LLMs in the Debian project, in accordance with a clearly defined code of conduct that may evolve (General resolution: LLM usage in Debian: Results). The eddie/AirVPN developers are also serious people, but they’re a small team → Please don’t put pressure on them. They’re professionals and they’re evolving just like everyone else. They know how they need to work...
-
ANSWERED trying to get air vpn to startup with linux machine
Staff replied to reader45's topic in Troubleshooting and Problems
Hello! It is not necessary, with the option you mention Eddie will start during the system boot either on Windows or Linux based on systemd. Starting from 2.26.2 it will start on SysV init based Linux boxes too (this is new: if you find again malfunctions on SysV init based systems please warn the developers on the thread or via ticket). If the Connect at startup option is also active, then Eddie will start AND connect during the system bootstrap. Of course you are free to start Eddie automatically in different, canonical ways on each system. Kind regards -
-
-
Eddie Desktop Edition 2.27 beta released
fishbasketballaries replied to Staff's topic in News and Announcement
Can no longer enable network lock if "Don't ask elevation every run" is enabled. It pops up with the error "Exception: State directory not available". Once that is disabled and Eddie is restarted then the network locks normally. Running Debian 13. https://eddie.website/report/6a485d91/ -
-
Hello, and thank you for this new beta version of eddie-ui. I just tested it on Devuan 5 (based on Debian 12), and unfortunately, the problem persists. The terminal output is more detailed and mentions a library file named “linux-vdso.so.1”. A `find` search shows that this binary does not exist on my machine. A search on https://packages.debian.org/ shows that this binary is not present in the official Debian repositories. demo@devuan5:~$ sudo find / -mount -regex ".*linux-vdso.so.1.*" demo@devuan5:~$ eddie-ui . 2026-09-04 03:43:44.415 - Eddie version: 2.27.1 / linux_x64, System: Linux, Name: Devuan GNU/Linux 5 (daedalus), Version: 5 (daedalus), Framework: 6.8.0.96 (tarball Wed Jan 15 10:20:48 UTC 2020); Framework: v4.0.30319 . 2026-09-04 03:43:44.461 - Command line arguments (1): path.resources="/usr/share/eddie-ui" . 2026-09-04 03:43:44.481 - Raise system privileges . 2026-09-04 03:43:44.483 - Elevated launch with method 'pkexec': /usr/lib/eddie-ui/eddie-cli-elevated . 2026-09-04 03:43:52.103 - Elevated helper report: linux-vdso.so.1 (0x00007ffdc4915000) . 2026-09-04 03:43:52.103 - libgtk3-nocsd.so.0 => /usr/lib/x86_64-linux-gnu/libgtk3-nocsd.so.0 (0x00007fb8773c9000) . 2026-09-04 03:43:52.103 - libpthread.so.0 => /lib/x86_64-linux-gnu/libpthread.so.0 (0x00007fb8773c4000) . 2026-09-04 03:43:52.103 - libstdc++.so.6 => /usr/lib/x86_64-linux-gnu/libstdc++.so.6 (0x00007fb877000000) . 2026-09-04 03:43:52.103 - libm.so.6 => /lib/x86_64-linux-gnu/libm.so.6 (0x00007fb8772e4000) . 2026-09-04 03:43:52.103 - libgcc_s.so.1 => /lib/x86_64-linux-gnu/libgcc_s.so.1 (0x00007fb8772c4000) . 2026-09-04 03:43:52.103 - libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x00007fb876e1e000) . 2026-09-04 03:43:52.103 - libdl.so.2 => /lib/x86_64-linux-gnu/libdl.so.2 (0x00007fb8772bd000) . 2026-09-04 03:43:52.103 - /lib64/ld-linux-x86-64.so.2 (0x00007fb877463000) F 2026-09-04 03:43:52.105 - Unable to obtain elevated privileges (required): Unable to start (already exit, exit code 0). Look https://eddie.website/support/elevation/ to address this issue. . 2026-09-04 03:44:48.868 - Shutdown in progress . 2026-09-04 03:44:48.876 - Shutdown complete
- Last week
-
I had to install ovpn-dco 2.8.6 manually to make it work. It kept installing 2.8.2 with an Eddie client
-
ANSWERED trying to get air vpn to startup with linux machine
reader45 replied to reader45's topic in Troubleshooting and Problems
Its ok have sorted the extra bits i needed in system settings. chatgpt gave me the answer. -
I still have this problem
-
ANSWERED trying to get air vpn to startup with linux machine
reader45 replied to reader45's topic in Troubleshooting and Problems
I ran a windows 10 machine up and installed on that, selected the same boxes and it started up as i imagined. Windows started up, airvpn started up and because i had "reconnect to last server" ticked it connected to server without me doing anything else. So what else do i need to do to make airvpn/eddie startup when the box is cold booted or rebooted ? -
ANSWERED Gluetun + qbittorrent + port forwarding not working
Staff replied to traerin's topic in Troubleshooting and Problems
Hello! The FIREWALL_VPN_INPUT_PORTS environment variable is not set, unless you set it in your GlueTun invocation command, therefore the incoming (unsolicited) packets on the tunnel VPN interface are dropped. See also: https://github.com/qdm12/gluetun-wiki/blob/main/setup/options/firewall.md Note that the other variables related to firewall and inbound ports that you set on the compose file do not affect the firewall rules for the VPN interface: FIREWALL_INPUT_PORTS pertains to the default interface. You might like to delete the related line as we bet you do not want your p2p software to reply to incoming packets from the Internet and disclose your real IP address VPN_PORT_FORWARDING_LISTENING_PORTS has a totally different purpose, it re-directs a port to a custom localhost port of your choosing and will break p2p software ability to receive incoming packets. Do not use this variable with torrent clients, or any other software that publicly announces its port, as that software would not be aware of the publicly visible port and would be announcing the private port instead. Delete that line and read the documentation here for more details: https://github.com/qdm12/gluetun-wiki/blob/main/setup/advanced/vpn-port-forwarding.md As a side note for you and all the readers using GlueTun: read GlueTun's good documentation if you haven't already done so! Kind regards -
ANSWERED Asus Merlin VPN Network Unreachable
Tech Jedi Alex replied to Keeble's topic in Troubleshooting and Problems
Please start your own and give as much info as you can on the problem, what you tried, what you try to achieve, etc.; this is a help thread for another user. Simple formality. Hope it won't deter you -
-
I believe, starting Eddie itself. The options don't enter Eddie into any autostart mechanisms, that must be done by yourself. Connect at startup means "when Eddie starts, connect immediately". Don't ask elevation every run means "when Eddie starts, don't ask for sudo password". Both options are essential for what you want to achieve, but you still need to start Eddie itself.
-
ANSWERED Eddie, unable to connect
Tech Jedi Alex replied to mmtunligit's topic in Eddie - AirVPN Client
I don't think it's the NIC's problem – at least in this case all systems will behave like that. -
ANSWERED Asus Merlin VPN Network Unreachable
Hotgloblin replied to Keeble's topic in Troubleshooting and Problems
Hope it's correct form to append to this thread for the sake of others? Or should I start a new one? I have just had this problem. Yes, I have ip6 disabled in Merlin. The issue is the AirVPN configurator is not inserting the ip4 only commands into the .opvn file even when "ip4 only" is selected in Configurator. I have to add the following to the .opvn file: pull-filter ignore "dhcp-option DNS6" pull-filter ignore "tun-ipv6" pull-filter ignore "ifconfig-ipv6" pull-filter ignore "route-ipv6" setenv UV_IPV6 no The last command being optional. Is this by design? I had been told security was enhanced with ip4 only set on the Merlin side. Per Perplexity AI: "Merlin currently does not route IPv6 traffic through an external OpenVPN client reliably, so enabling IPv6 on the router while relying on OpenVPN can recreate the leak risk. The safest configuration for your existing hardware and goal is therefore to block IPv6 rather than attempt to tunnel it". But this then causes a conflict with the Configurator generated .opvn file causing the vpn not to load. Maybe because no one selects ip4 only in the Configurator any more?! Is this AI security claim false and should I just include ip6 in both Merlin and the Configurator?
