benfitita 39 Posted ... My apologies, App Store works now. I guess it must have been a temporary issue or Apple indeed is blocking the server I was using at the time. BTW it great that there's a higher limit of devices, so DNS settings can be better customized for various use cases. 1 Staff reacted to this Quote Share this post Link to post
Agrock 1 Posted ... Just came across this feature and had a mini-heart attack thinking I've been jumping through hoops for years to do my own DNS filtering because I simply didn't realise AirVPN could do it 😀 Good to know it's a new feature, thank you guys for all the good work as usual! I do have a question - would you ever consider offering DNS over TLS for this, potentially with custom per-user domains to differentiate between configs, a la NextDNS? I semi-understand the complexities involved, as well as that Air is a VPN and not a DNS provider and this verges on being an entirely separate service, so I fully understand if the answer is a hard no, but it would be fantastic to have. FWIW my use case is that, on Android, I need to run some apps outside the VPN (like most people I assume). Therefore, even with DNS filtering through Air, those apps would be free to phone home/display ads without DoT. So currently I'm "forced" to use NextDNS. It would be a lot less of a problem if Android allowed custom DNS priority, so connections over the VPN used the VPN DNS despite DoT being configured, but alas AFAICT that is not the case and will not be anytime soon. Quote Share this post Link to post
Staff 9972 Posted ... @Agrock Hello! DNS over TLS is supported since several months ago. It is almost useless since plain DNS queries to our VPN DNS, and their replies, are anyway encrypted and authenticated because they stay in the tunnel, but you might need DoT for peculiar configurations. Check the usual specs page for more details:https://airvpn.org/specs You can define anyway custom per "device" (i.e. client certificate/key pair) block lists, personalized exceptions and blocks, regardless of the fact you use DoT or not. Kind regards Quote Share this post Link to post
NoMercy1290 3 Posted ... Hello! Thank you very much for this feature! A question about updating the lists: Is there a job that updates the lists? Currently the lists is relatively old. Quote Share this post Link to post
BigX 1 Posted ... Hello Perhaps I'm just being dumb but I can't see how to simply turn the block list on or off. It appears that the block list is on by default and to turn it off requires: 1) Selecting "Customize account DNS settings" 2) Deselect all lists Am I missing something obvious? Thank you. Quote Share this post Link to post
spinmaster 30 Posted ... 19 hours ago, BigX said: Perhaps I'm just being dumb but I can't see how to simply turn the block list on or off. It appears that the block list is on by default and to turn it off requires: 1) Selecting "Customize account DNS settings" 2) Deselect all lists Am I missing something obvious? Client Area -> DNS "Customize account DNS settings": enabled (green slider). Then you can enable (= again, slider set to green) or disable each individual list. Did you try this? Quote Share this post Link to post
Staff 9972 Posted ... On 11/28/2021 at 12:07 PM, NoMercy1290 said: Hello! Thank you very much for this feature! A question about updating the lists: Is there a job that updates the lists? Currently the lists is relatively old. Thank you for your great feedback and the head up. Lists should have been updated every 24 hours but the procedure started failing recently. We are working on it to detect the problem and restore the normal update every 24 hours. EDIT: problem detected and fixed. Kind regards 2 OpenSourcerer and spinmaster reacted to this Quote Share this post Link to post
NoMercy1290 3 Posted ... 10 minutes ago, Staff said: Thank you for your great feedback and the head up. Lists should have been updated every 24 hours but the procedure started failing recently. We are working on it to detect the problem and restore the normal update every 24 hours. Kind regards Thanks a lot for the update and the great support. Kind regards Quote Share this post Link to post
BigX 1 Posted ... (edited) 8 hours ago, spinmaster said: Client Area -> DNS "Customize account DNS settings": enabled (green slider). Then you can enable (= again, slider set to green) or disable each individual list. Did you try this? Hi spinmaster Thanks for your response. I did do that while experimenting. However, I'm finding the wording confusing. Really just hoping someone can clarify my understanding Let me try to explain my confusion. For example in the Client Area (Dashboard like page) I currently have the following, DNS DNS settings, block lists. Customized This to me does not imply that the block list is off/disabled. I take it to mean that default block lists as defined by AirVPN are active. Does this actually mean that no block lists are applied? To quote from the DNS settings page, "Customize account DNS settings - Otherwise, default settings by AirVPN are used". What are the "default settings"? That doesn't sound like off/disabled. Sorry if I'm being a bit thick In contrast, the API in the Client Area shows, API Not active This is clearly off/disabled. So to disable (turn off) the block list requires enabling "customize" and then disable all the individual lists? So the following with all lists disabled means that all blocking is off. DNS DNS settings, block lists. Customized Edited ... by BigX Clarification Quote Share this post Link to post
OpenSourcerer 1435 Posted ... Hover over that little pictogram with your mouse, will you? 1 hour ago, BigX said: What are the "default settings"? That doesn't sound like off/disabled. Default = "The air to breathe the real Internet" Customized = "The air to breathe the filtered Internet" I do admit that at the very first I asked myself what it exactly means, too, but it quickly occured to me that it's used in the same way as other boolean values on the website, on IPLeak, in Eddie. Its meaning is therefore unambiguous. 1 1 spinmaster and BigX reacted to this Quote Hide OpenSourcerer's signature Hide all signatures NOT AN AIRVPN TEAM MEMBER. USE TICKETS FOR PROFESSIONAL SUPPORT. LZ1's New User Guide to AirVPN « Plenty of stuff for advanced users, too! Want to contact me directly? All relevant methods are on my About me page. Share this post Link to post
MadHack 1 Posted ... Hello to all members, I´m testing the Wireguard protocol in my laptop and Iphone, using the native Wireguard app. In the laptop all working very well, fast, very fast, love the Wireguard implementation. In the Iphone work great all, but the DNS Block List don´t work well. For example when i connect in the fist time when i add or change something in the DNS preferences, take some seconds to reflect in all active connections. Work well when i visit Browserleaks.com. When i disconnect and choose other server and go again to Browserleaks, appear the ads. I don´t know what happen, block at first and when i choose other country don´t work. Is my end problem? What im doing wrong? Thanks for all implementations Quote Share this post Link to post
NoMercy1290 3 Posted ... Hello @Staff It seems that the updates of the lists are currently no longer working. Thanks for your help! Quote Share this post Link to post
Staff 9972 Posted ... @NoMercy1290 Thank you! The problem has been resolved. Kind regards 1 NoMercy1290 reacted to this Quote Share this post Link to post
IG-11 5 Posted ... Hello @Staff, can you please clarify how exactly lists updating works - your system should update all lists every 24h or update occurs only if source (list itself) was changed? I'm asking because for example my client panel shows that Ads, Malware and Crypto lists were updated today but on the other hand Dating, Gambling and some other community lists - one month or two months ago. Also in the panel there is information that lists are updated every hour so that should probably be updated as well. Quote Share this post Link to post
Air4141841 24 Posted ... I guess I should have tested this more until I said it was working for me. running pfsense with one device in my customer account. All my devices that use Air I set a static dns ip of 10.4.0.1 and it has always worked perfectly for years.. under client / dns it’s green. Went to a site I figured Would be blocked, Nope, tried another not blocked… read more and then went to client / devices/ detailed and enabled the same dns filter. Gave it 5 minutes still not blocked i ran a ifconfig from command prompt and used the default gateway… instead of 10.4.0.1 and it immediately worked. now I know Quote Share this post Link to post
NoMercy1290 3 Posted ... Hello @Staff I just noticed that on the DNS list page the OSID list is missing. Have you taken out the list? Kind regards Quote Share this post Link to post
Staff 9972 Posted ... @NoMercy1290 Hello! Correct, since the list "exploded" to more than a million entries yesterday (from a few hundred thousands) a security system disabled it. Today it has shrunk again to 300'000 entries. The list is now available. Kind regards 1 NoMercy1290 reacted to this Quote Share this post Link to post
NoMercy1290 3 Posted ... @Staff The OSID List is missing again. Is there a chance that we get this list back? Kind regards Quote Share this post Link to post